SYN spoofing

Randy Bush randy at
Mon Aug 2 15:09:55 UTC 1999

> How hard is it really to put a filter on your outbound links that says
> drop all ip traffic heading out these links that isn't from my IP space?

trivial.  only one gotcha.  if it is a backbone router, it will fall over
dead.  beyond that, not a problem.

backbone level traffic can not be packet filtered by current real routers.
but we've had this discussion a few times already.


