[194732] in North American Network Operators' Group
Re: BCP38/84 and DDoS ACLs
daemon@ATHENA.MIT.EDU (Randy Bush)
Fri May 26 19:08:04 2017
X-Original-To: nanog@nanog.org
Date: Sat, 27 May 2017 08:07:57 +0900
From: Randy Bush <randy@psg.com>
To: Roland Dobbins <rdobbins@arbor.net>
In-Reply-To: <261BE93D-1E52-4F9F-8C47-49D842134226@arbor.net>
Cc: North American Network Operators' Group <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org
to be honest, i do not block chargen etc at my borders; i scan hosts
and turn off silly services on the hosts. but i do not have myriads of
hosts in a soft gooey inside.
what i block at my borders are 135-139, 161 (except for holes for
measurement stations), 445, 514, stuff such as that.
ykmv
randy