Sun Apr 19 22:56:26 UTC 1998

You could always "deny icmp any aaa.bbb.ccc.ddd www.ccc.nnn.mmm log" on
your cores.  Deny ICMP from critical portions of your network.  Create a
little script which tail -fs the log, parses it, sorts it and counts it.
If the script counts more then xxx hits on a certain IP or a certain
number of IPs on your network from the same source or a multiple sources
on the same network, you have your upstream.  Once you have them, you can
call them and ask them to do the same until you find the real source.

This will not protect against someone smurfing your dialup users and they
can do just as much damamge as the former, but they are more likely to
bitch if they can't ping so it's a toss up.

On Sat, 18 Apr 1998, Dean Anderson wrote:

