[68263] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Source address validation (was Re: UUNet Offer New Protection

daemon@ATHENA.MIT.EDU (fingers)
Sun Mar 7 13:09:31 2004

Date: Sun, 7 Mar 2004 20:08:51 +0200 (SAST)
From: fingers <fingers@fingers.co.za>
To: nanog@merit.edu
In-Reply-To: <Pine.GSO.4.58.0403070212071.8056@clifden.donelan.com>
Errors-To: owner-nanog-outgoing@merit.edu


just a question

why is DDoS the only issue mentioned wrt source address validation?

i'm sure there's other reasons to make sure your customers can't send
spoofed packets. they might not always be as news-worthy, but i feel it's
a provider's duty to do this. it shouldn't be optional (talking
specifically about urpf on customer interfaces, loose where needed)

home help back first fref pref prev next nref lref last post