[169531] in North American Network Operators' Group
Re: Managing ACL exceptions (was Re: Filter NTP traffic by packet
daemon@ATHENA.MIT.EDU (Dobbins, Roland)
Fri Feb 28 21:45:43 2014
From: "Dobbins, Roland" <rdobbins@arbor.net>
To: NANOG <nanog@nanog.org>
Date: Sat, 1 Mar 2014 02:41:39 +0000
In-Reply-To: <35E3BB4D-8C6B-4A8A-AEC1-FF729124ABEB@comcast.net>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Mar 1, 2014, at 9:14 AM, Keegan Holley <no.spam@comcast.net> wrote:
> +1 in my experience uRPF get=92s enabled, breaks something or causes conf=
usion (usually related to multi-homing) and then get=92s disabled.
Enabling loose-check - even with allow-default - is useful solely for S/RTB=
H, if nothing else.
-----------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>
Luck is the residue of opportunity and design.
-- John Milton