[163107] in North American Network Operators' Group
Re: High throughput bgp links using gentoo + stipped kernel
daemon@ATHENA.MIT.EDU (Valdis.Kletnieks@vt.edu)
Sun May 19 20:33:38 2013
To: Seth Mattinen <sethm@rollernet.us>
In-Reply-To: Your message of "Sun, 19 May 2013 16:42:23 -0700."
<5199635F.1050606@rollernet.us>
From: Valdis.Kletnieks@vt.edu
Date: Sun, 19 May 2013 20:32:55 -0400
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
--==_Exmh_1369009975_2644P
Content-Type: text/plain; charset=us-ascii
On Sun, 19 May 2013 16:42:23 -0700, Seth Mattinen said:
> On 5/19/13 4:27 PM, Ben wrote:
> > Do you actually need stateful filtering? A lot of people seem to think
> > that it's important, when really they're accomplishing little from it,
> > you can block ports etc without it.
>
>
> I believe PCI compliance requires it, other things like it probably do too.
It's the rare ISP who's border routers are in-scope for PCI compliance.
--==_Exmh_1369009975_2644P
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001
iQIVAwUBUZlvNgdmEQWDXROgAQL4uxAAtbk8t2K1bmhPMUBBfEoHxuWmz95TeOYY
egufsqY2V7QOjiEkAjMgToSasYloO4/pzC+CGJH0Tt6I775CMrGeASK76tycMZrs
7osrKCf6mptbzm1NvAnfiptuxcZH6SDWe9Ly66qqV5eU7t9IK5BdCT6Lyen99awM
keQ6+zVej4OUjVjV9C02CgJ60S3CjM6OnzvPFa4e4HsR1IZyi+0HNy/0UH0i2gi5
4ScLs/zsLJ6HJsirzxFJiHBu6d4QQfvHMHbvg/JgjLU8FDuspi8DXiY7mk0bJ3vy
l3KzWY61bVSuvqHyYCjyaULpfwk7mPua3TehfmeBa+qHXLvpctuRheYmEEeta44E
ZE8Bgsxttd+5i/3MVcSZgeU43dIg59l571+n22zrsHss84O7+WLqZMZy3ROStJN4
bpY9BkfP+48+fO5I6Xz11N7NoEOSq9aJyHN4arUQoHd5JgSrU/O++W4eImRXHinm
l0LEYWLOHhddcUvCyL1vv9p3jZkkO3qgdhf1Wj03lx+1dtz4p05ElvOM5vDp2p/f
eMouTjNVCucZn3dwF5hiPy/Yc4J0H++OhZ7znZ8jYepcNydCDsppgWlveC8maU4q
9s3lVCOMpMTwBHD1neF5Ewgg3NXqDfRte6Dm5gpToof2gt0ftM/MagAOFZbX85dC
rFMY39hGLDk=
=eHUy
-----END PGP SIGNATURE-----
--==_Exmh_1369009975_2644P--