[44220] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Rate limiting UDP,Multicast,ICMP

daemon@ATHENA.MIT.EDU (Thomas Gainer)
Tue Nov 13 12:42:29 2001

Message-ID: <E6F85CA58D2A834E99B1683C05BC7987025F95B5@mail.corp.com>
From: Thomas Gainer <TGainer@e-xpedient.com>
To: nanog@merit.edu
Date: Tue, 13 Nov 2001 12:42:01 -0500
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Errors-To: owner-nanog-outgoing@merit.edu


A little more information.  We sell 100Mb Ethernet pipes to the Internet.
(Yes, there are a few of us left).  A fair number of these customers are
small businesses.  Usually, they have servers but very little IT support and
even less IT know how.  My thought is to rate limit UDP and ICMP at the
customer port to no more than 3Mb/s so WHEN (not if) a customer is
compromised, the effects are somewhat limited and my MAN pipes have some
measure protection.  The question is, what am I not thinking of?  DNS, TFTP
and such should all operate virtually unaffected, as they are not bandwidth
hungry services.

Thomas

home help back first fref pref prev next nref lref last post