[23782] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: address spoofing

daemon@ATHENA.MIT.EDU (Phillip Vandry)
Fri Apr 23 14:10:29 1999

Date: Fri, 23 Apr 1999 14:08:55 -0400 (EDT)
From: Phillip Vandry <vandry@Mlink.NET>
To: nanog@merit.edu (North America Network Operators Group)
In-reply-to: Your message of "Fri, 23 Apr 1999 13:55:51 EDT."
             <m10akB5-000g7rC@most.weird.com> 
Errors-To: owner-nanog-outgoing@merit.edu


> > My outbound access lists block it, so you should never see 1918
> > sources coming from me.  You should see "* * *" instead, even
> > if you don't block them coming in to your net.
> 
> I think this sucks big-time.  It wouldn't be quite so bad if traceroute
> were the only thing that were broken by it (though I do like my
> traceroutes to work properly too), but when all ICMP traffic from such a
> router is hosed, and one of the links my packets are trying to hop onto
> through such a router is down, then I'm a particularly unhappy camper
> (if I could see the !H or !N I'd still be unhappy of course, but not

...and I'd certainly like to see my ICMP unreachables which are vital to
path MTU discovery not blocked.

-Phil


home help back first fref pref prev next nref lref last post