Merit Network
Can't find what you're looking for? Search the Mail Archives.
  About Merit   Services   Network   Resources & Support   Network Research   News   Events   Home

Discussion Communities: Merit Network Email List Archives

North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Effects of traffic shaping ICMP (&c.)

  • From: Mark R. Lindsey
  • Date: Wed Dec 02 16:40:11 1998

Howdy,

When our network is being smurfed, we can call our ISPs and have them
setup an access list to block ICMP. That fixes the problem, but it
creates another (obvious) problem.

Could traffic shaping, or similar QoS configurations, be used to solve
such issues in a more general way? For example, if my source of packet
flooding is ICMP, then I'd like to be able to dedicate as much as 1/10th
(e.g.) of the bandwidth of each link to ICMP. That's plenty of ICMP, but
it's not so much that an attack using ICMP would be effective.

My question, stated briefly, is this: can you solve generic
homogenous-packet-flood problems with QoS and/or traffic shaping (if the
two can be truly distinguished), in general? If so, are current routers
capable of doing it? What would be the effect of doing so on dialup
links and backbones?

---
Mark R. Lindsey, mark@datasys.net
Internet Engineering, DSS Online LLC
Voice: 912.241.0607x200, Fax: 912.241.0190 (US)




Discussion Communities


About Merit | Services | Network | Resources & Support | Network Research
News | Events | Contact | Site Map | Merit Network Home


Merit Network, Inc.