[162216] in North American Network Operators' Group
Re: ICMP Redirect on Resolvers
daemon@ATHENA.MIT.EDU (shawn wilson)
Sat Apr 6 10:38:18 2013
In-Reply-To: <CAAAwwbXKePOGTnWpGEfHYubJ5ef9_Fb0K-F3BB8yu9xETb8HKw@mail.gmail.com>
Date: Sat, 6 Apr 2013 10:38:06 -0400
From: shawn wilson <ag4ve.us@gmail.com>
To: Jimmy Hess <mysidia@gmail.com>
Cc: North American Network Operators Group <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Apr 6, 2013 3:13 AM, "Jimmy Hess" <mysidia@gmail.com> wrote:
>
> Failing all that, if the LANs are large, and a large number of ICMP
> redirects would occur, it may be preferrable to turn ICMP redirects
> off for those LANs on their routers
>
What would break if u dropped all ICMP packets with redirects on public
facing boxes?