ietf
[Top] [All Lists]

Re: Internet SYN Flooding, spoofing attacks

2000-02-11 21:40:02
On Fri, 11 Feb 2000 21:09:47 EST, Paul Ferguson said:
We (at least cisco, anyways) already have a knob for this:

  [no] ip verify unicast reverse-path

We call it Unicast RPF.

Paul:

What are the chances of setting up "The Next Release" of IOS
so that for simple configs (for example, a customer backbone and
one upstream link to a provider) the knob would automagically default
to Doing The Right Thing?  I of course am writing as a non-expert on
the innnards of IOS, and I'm expecting flame-fests regarding "simple
config" and "Right Thing".

No, it's not a total fix.  It won't fix everything.  It may not
even be possible.  But it certainly would be nice. ;)

                                Valdis Kletnieks
                                Operating Systems Analyst
                                Virginia Tech