address spoofing

Randy Bush randy at
Fri Apr 23 01:33:24 UTC 1999

everybody seems to be focussed on the 1918 space packets and the
explanations seem half reasonable.  as Daniel Senie <dts at> said,
the rules of the road say i should not be seeing packets from 1918 space.
i.e. at best these come from broken places.

but the uglier symptoms are packets from my own address space

    deny ip any (6 matches)

the loopback network

    deny ip any (375 matches)

and attempts on 111 and 2049

    deny udp any any eq sunrpc (9 matches)
    deny tcp any any eq 2049 (494 matches)


More information about the NANOG mailing list