Firewall Wizards mailing list archives

Re: DDOS Countermeasures RFC


From: Ryan Russell <ryan () securityfocus com>
Date: Wed, 31 Jan 2001 09:40:32 -0700 (MST)

On Wed, 31 Jan 2001 jan () nil si wrote:

Generally, it's hard to automagically decide what a leaf subnet is, if
your router configurations are not by-the-book or there is asymmetric
routing in place.

You don't have to have the router try and determine if it's a leaf or
not.. just leave it on by default, and require the network admin to know
that they have to shut it off in order to do a router-to-router interface.

                                                Ryan

_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


Current thread: