smurf

Wayne Bouchard web at typo.org
Sat Dec 6 05:05:13 UTC 1997


Okay, so I'm now blocking 45 megs of icmp echo-reply packets at my
borders.. At one point, this was 80,000 packets/sec. (No, I'm
not exagerating.)


<SoapBox>

For anyone who has not, PLEASE DISABLE DIRECTED BROADCASTS!
Tell a friend.. If you sell routers to clients and/or you
configure them, include that in your default configuration.
Encourage people to filter inbound ICMP where possible..
Do whatever it takes to work with your customer/peers to
put a stop to this kind of abuse. Of all the attacks to date,
this (and the recent land.c which is a different issue together)
threaten the most disruption of internet services. With ISDN and
DSL, users have the bandwidth necessary to generate even more
dangerous levels of traffic. If you don't think this issue affects
you, it does. If you're not a target, your probably being used
as a source.

</SoapBox>

We thank you for your support..


----------------------------------------------------------------------
Wayne Bouchard                             GlobalCenter
web at primenet.com                           
Primenet Network Operations                Internet Solutions for
(602) 416-6422   800-373-2499 x6422        Growing Businesses
FAX: (602) 416-9422
http://www.primenet.com                    http://www.globalcenter.net
----------------------------------------------------------------------



More information about the NANOG mailing list