nanog mailing list archives

ACLs / Filter Lists - Best Practices


From: John McBrayne <mcbrayne () caspiannetworks com>
Date: Tue, 27 Nov 2001 15:37:18 -0800


Is anyone aware of any current "best practices" related to the
recommended set of filtering rules (Cisco ACL lists or Juniper filter
sets) for reasons of Security, statistics collection, DoS attack
analysis/prevention, etc.?  I'm curious to see if there are any such
recommendations for Tier 1/Tier 2 backbone routers, peering points,
etc., as opposed to CPE terminations or Enterprise/LAN equipment
recommendations.

Actual config file examples would be great, if they exist.

Thanks;
..john


Current thread: