nanog mailing list archives

Re: Re[4]: SYN floods (was: does history repeat itself?)


From: Curtis Villamizar <curtis () ans net>
Date: Thu, 12 Sep 1996 22:18:35 -0400


In message <234661D0.3000 () usr com>, Pat Calhoun writes:
     Alexis,
     
        However if you are filtering on your outbound router to the net, 
     there is still the possbility that a malicious user could spoof 
     addresses as long as they belong to your address space. By moving the 
     filter out to the edge (when you have the equipment) this eliminates 
     that problem as well.
     
     Pat R. Calhoun                                e-mail: pcalhoun () usr com 
     Project Engineer - Lan Access R&D                phone: (847) 933-5181 
     US Robotics Access Corp.


Know what ISP the traffic is coming from is enormously useful compared
to "its coming from NSP X" or worse yet, "its coming from someone on
Mae-East".  That's often were we start from these days.

Curtis
- - - - - - - - - - - - - - - - -


Current thread: