[125593] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Rate of growth on IPv6 not fast enough?

daemon@ATHENA.MIT.EDU (Florian Weimer)
Tue Apr 20 06:28:43 2010

From: Florian Weimer <fw@deneb.enyo.de>
To: Bryan Fields <Bryan@bryanfields.net>
Date: Tue, 20 Apr 2010 12:27:54 +0200
In-Reply-To: <4BCCD328.1030907@bryanfields.net> (Bryan Fields's message of
	"Mon, 19 Apr 2010 18:03:20 -0400")
Cc: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

* Bryan Fields:

> Yes, but I was showing what a great DDOS attack method it would be
> too ;)

The beauty of flow-based forwarding (with or without NAT) is that
several types of denial-of-service attacks tend to hurt close to the
packet sources, and not just close to the victim.  As far as the whole
system is concerned, this is a very, very good thing.


home help back first fref pref prev next nref lref last post