Recent DNS attacks from China?
Rob.Vercouteren at kpn.com
Rob.Vercouteren at kpn.com
Fri Dec 2 15:40:52 UTC 2011
Since it is spoofed traffic we block the "source", so not participating in flooding the real ip address.
The real issue is verify unicast reverse path not being implemented. So that the ip addresses cannot be spoofed!
(unless we are dealing with some major unknown vurlnerabilities in our infrastructure)
After a few days we will unblock again.
Regards,
Rob Vercouteren
More information about the NANOG
mailing list