nanog mailing list archives

Re: BCP38/84 and DDoS ACLs


From: Randy Bush <randy () psg com>
Date: Sat, 27 May 2017 08:07:57 +0900

to be honest, i do not block chargen etc at my borders; i scan hosts
and turn off silly services on the hosts.  but i do not have myriads of
hosts in a soft gooey inside.

what i block at my borders are 135-139, 161 (except for holes for
measurement stations), 445, 514, stuff such as that.

ykmv

randy


Current thread: