[50593] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: NSPs filter?

daemon@ATHENA.MIT.EDU (Chris Woodfield)
Mon Aug 5 14:35:11 2002

Date: Mon, 5 Aug 2002 14:30:12 -0400
From: Chris Woodfield <rekoil@semihuman.com>
To: bmanning@karoshi.com
Cc: Abdullah Bin Hamad - Arabian <Arabian@ArabChat.Org>,
	nanog@merit.edu
In-Reply-To: <20020805031935.GA25577@semihuman.com>
Errors-To: owner-nanog-outgoing@merit.edu



--ZPt4rx8FFjLCG7dd
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

I'll clarify this...I already noted that antispoof filtering is an exceptio=
n,=20
and I'll agree that RPF fits loosely under the antispoofing definition as w=
ell,=20
albiet in the other direction.

-C

On Sun, Aug 04, 2002 at 11:19:35PM -0400, Chris Woodfield wrote:
> IMO, Commercial ISPs should never filter customer packets unless=20
> specifically requested to do so by the customer, or in response to a=20
> security/abuse incident.=20
>=20
> Consumer ISPs are much more likely to have clauses in the AUPs that are=
=20
> enforced premptively via packet filtering - antispoof filters (honestly,=
=20
> antispoof filtering is, IMHO, the one expection to my "commercial ISPs=20
> should not filter" rule), port blocks to prevent customers running=20
> servers, outbound SMTP blocks to off-provider systems to stop direct-to-M=
X=20
> spamming, ICMP rate limiting, et al. All of which are fine by me as long=
=20
> as they clearly assert their right to do so in their AUP - that is, as=20
> long as there's a comparable provider I can use instead.
>=20
> -C
>=20
> On Sun, Aug 04, 2002 at 02:37:12PM +0000, bmanning@karoshi.com wrote:
> >=20
> > > Good day,
> > >=20
> > > What NSPs do filter packets, and can really deal with DoS and DDoS at=
tacks?
> > >=20
> > > -Abdullah Bin Hamad A.K.A Arabian
> >=20
> > 	The shorter shorter list would be the NSPs that do NOT filter
> > 	packets.  I can't think of an NSP that does not filter.
> >=20
> > --bill



--ZPt4rx8FFjLCG7dd
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE9TsQ0qP/YiunDNcERAuWmAKDON6f4Xx3i+/1byGj9vLh6IjNnoQCeKn77
zDOq8XxRMYMrfJsiVwXgquc=
=biSR
-----END PGP SIGNATURE-----

--ZPt4rx8FFjLCG7dd--

home help back first fref pref prev next nref lref last post