nanog mailing list archives

Re: Possible Sudden Uptick in ASA DOS?


From: "Roland Dobbins" <rdobbins () arbor net>
Date: Thu, 09 Jul 2015 02:24:32 +0700

On 9 Jul 2015, at 0:43, Mark Mayfield wrote:

However, this makes me consider the need to more aggressively ACL inbound traffic at the router level before these particular firewalls, which I can do, and may help mitigate such events,

Spot-on - reduce the state-surface as much as possible.

so thank you for the reminder!

Sorry for the repeat, but glad the preso was helpful!

;>

-----------------------------------
Roland Dobbins <rdobbins () arbor net>


Current thread: