nanog mailing list archives

Re: Effective ways to deal with DDoS attacks?


From: Ralph Doncaster <ralph () istop com>
Date: Mon, 6 May 2002 19:39:44 -0400 (EDT)


On Mon, 6 May 2002, Valdis.Kletnieks () vt edu wrote:

On Mon, 06 May 2002 19:04:11 EDT, Ralph Doncaster said:

IP Tunneling - it often makes more sense to send packets out that have a
source address reachable only through the tunnel.

But aren't those source addresses hidden *inside* the encapsulation, and
what's visible to routers are the source/dest IPs of the tunnel itself?

What I'm saying is that if something comes in through the tunnel, the
shortest route to the destination is often not to go back out through the
tunnel.


Current thread: