nanog mailing list archives

Re: DoS attacks, NSPs unresponsiveness


From: Valdis.Kletnieks () vt edu
Date: Thu, 02 Nov 2000 10:29:34 -0500

On Thu, 02 Nov 2000 09:59:04 EST, Mark Mentovai <mark-list () mentovai com>  said:
This can't go on forever.  I'd like to spread the clue about ingress
filtering, and am willing to commit time to the cause.  Is anyone with me?

The problem is that for many ISPs, I fear the only way to get them to
implement 2827-style filtering is for their upstreams to implement a
policy of fascist-mode ingress filtering - "We see a bogon packet that
your site should have filtered, we pull the plug on your link till you
fix it".

Time alone won't be enough.  Bring a baseball bat.  And a spare bat.

-- 
                                Valdis Kletnieks
                                Operating Systems Analyst
                                Virginia Tech


Attachment: _bin
Description:


Current thread: