nanog mailing list archives
Re: [arin-announce] IPv4 Address Space (fwd)
From: Alex Yuriev <alex () yuriev com>
Date: Wed, 29 Oct 2003 14:24:16 -0500 (EST)
I think the other point that may be escaping some people, is that as more and more connections take on this VPN-like quality, as network operators we lose any visibility into the validity of the traffic itself.
As the network operators, we move bits and that is what we should stick to moving. We do not look into packets and see "oh look, this to me looks like an evil application traffic", and we should not do that. It should not be the goal of IS to enforce the policy for the traffic that passes through it. That type of enforcement should be left to ES.
Imagine how much more painful SQL Slammer would have been, if all the traffic was encapsulated in port 80 between sites, and only hit port 1434 locally?
How do you know which traffic is good and which traffic is evil?
At least today, we can decide that 92 byte ICMP echo-request packets are invalid, and drop them; or that for the most part, packets destined to port 1434 should be discarded as quickly as possible.
How does you IS know that a _particular_ ES uses port 1434 for? Alex
Current thread:
- Re: [arin-announce] IPv4 Address Space (fwd), (continued)
- Re: [arin-announce] IPv4 Address Space (fwd) David Raistrick (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Jack Bates (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Crist Clark (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) E.B. Dreger (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) Scott McGrath (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) Paul Timmins (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) Scott McGrath (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) Leo Bicknell (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) matt (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Alex Yuriev (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) william (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Alex Yuriev (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) matt (Oct 29)
- traffic engineering (or lack of thereof) Alex Yuriev (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) william (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Alex Yuriev (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) matt (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) Alex Yuriev (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) Chris Parker (Oct 30)
- Re: [arin-announce] IPv4 Address Space (fwd) Alex Yuriev (Oct 30)