Merit Network
Can't find what you're looking for? Search the Mail Archives.
  About Merit   Services   Network   Resources & Support   Network Research   News   Events   Home

Discussion Communities: Merit Network Email List Archives

North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: smurf's attack...

  • From: Jon Green
  • Date: Fri Sep 05 16:09:08 1997

On Fri, 5 Sep 1997 15:24:58 -0400, jordyn@bestweb.net writes:

>We're also using the following extended access list (along with
>anti-spoofing filters) to prevent smurf attacks from originating from our
>network:
>
>access-list XXX deny ip any 0.0.0.255 255.255.255.0


Folks, this is a bad idea.  There are lots of completely valid IP
addresses out there that end in .255.  True, most of them that
end in .255 ARE broadcast addresses, but if people implement this
kind of filtering on a large scale, it really breaks classless IP.

But that's just IMHO. :)

-Jon

     -----------------------------------------------------------------
    *      Jon Green            *         "Life's a dance             *
   *   jcgreen@netINS.net       *          you learn as you go"        *
  *  Finger for Geek Code/PGP   *                                       *
 *  #include "std_disclaimer.h" * http://www.netins.net/showcase/jcgreen *
 -------------------------------------------------------------------------




Discussion Communities


About Merit | Services | Network | Resources & Support | Network Research
News | Events | Contact | Site Map | Merit Network Home


Merit Network, Inc.