nanog mailing list archives
RE: Interesting new spam technique - getting a lot more popular.
From: "Lincoln Dale" <ltd () interlink com au>
Date: Wed, 14 Jun 2006 22:03:55 +1000
is it really that hard to make your foudry/extreme/cisco l3 switch vlan and subnet??? Is this a education thing or a laziness thing? Is this perhaps covered in a 'bcp' (not even an official IETF thing, just a hosters bible sort of thing) ?
Subnets aren't exactly good for address space usage. For Cisco kit, there are numerous nerd knobs that can be deployed that would seemingly mitigate this spam technique. In short, IP Source Guard ("stop malicious people from using IP addresses that weren't assigned to them"), Port Security ("limit # of mac addresses on a given port to X") and Dynamic ARP Inspection ("discard bogus arp packets"). Combined with things like Private VLANs (allow different customers to share the same subnet but restrict them being able to talk/see one another), there are ways of securing things. Of course, just like everything its up to folks to deploy them. Many of these knobs aren't safe or practical for "default" settings. I'm sure other vendors have similar features also. Yes, these have been presented on numerous times within Cisco forums (e.g. Networkers) as best practice & are typically very well attended. Not necessarily by the all the folk that need to, I guess. :( cheers, lincoln.
Current thread:
- Re: Interesting new spam technique - getting a lot more popular., (continued)
- Re: Interesting new spam technique - getting a lot more popular. Mikael Abrahamsson (Jun 15)
- RE: Interesting new spam technique - getting a lot more popular. Kristal, Jeremiah (Jun 15)
- RE: Interesting new spam technique - getting a lot more popular. Mikael Abrahamsson (Jun 15)
- RE: Interesting new spam technique - getting a lot more popular. Kristal, Jeremiah (Jun 15)
- Re: Interesting new spam technique - getting a lot more popular. Danny McPherson (Jun 19)
- Re: Interesting new spam technique - getting a lot more popular. chuck goolsbee (Jun 15)
- Re: Interesting new spam technique - getting a lot more popular. Matt Buford (Jun 15)
- Re: Interesting new spam technique - getting a lot more popular. chuck goolsbee (Jun 15)
- Re: Interesting new spam technique - getting a lot more popular. Chris Adams (Jun 15)
- RE: Interesting new spam technique - getting a lot more popular. andrew2 (Jun 15)
- RE: Interesting new spam technique - getting a lot more popular. Lincoln Dale (Jun 14)
- Re: Interesting new spam technique - getting a lot more popular. Florian Weimer (Jun 14)
- Re: Interesting new spam technique - getting a lot more popular. Richard Z (Jun 15)
- Re: Interesting new spam technique - getting a lot more popular. Payam Chychi (Jun 13)
- RE: Interesting new spam technique - getting a lot more popular. Edward B. DREGER (Jun 13)
- Re: Interesting new spam technique - getting a lot more popular. Warren Kumari (Jun 14)
- Re: Interesting new spam technique - getting a lot more popular. Mark Smith (Jun 15)