Firewall Wizards mailing list archives

Re: IPv6 support in firewalls


From: "Steven M. Bellovin" <smb () cs columbia edu>
Date: Fri, 24 Aug 2007 11:57:09 -0400

On Thu, 23 Aug 2007 20:27:45 -0400
"Marcus J. Ranum" <mjr () ranum com> wrote:

Steven M. Bellovin wrote:
You can always send broadcast pings on
each LAN

Does that work in V6? Sounds like a good DDoS amplifier - any place
where "one packet goes out, zillions come back" is a really useful
bit of asymmetry.

I said "broadcast ping", not "directed broadcast ping".  The latter
would be dangerous indeed...


                --Steve Bellovin, http://www.cs.columbia.edu/~smb
_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: