Solution: Re: Huge smurf attack

Brett Frankenberger brettf at netcom.com
Wed Jan 13 23:56:13 UTC 1999


:: Brandon Ross writes ::
> 
> Doing something like this, similar to the serveral suggestions to
> filter all .0 and .255 addresses, is an attempt to fix the symptom
> instead of the real problem.

So is forcing vendors to make the equivalent of "no ip
directed-broadcast" the default.  The problem is that dolts configure
routers.  The symptom is "ip directed-broadcast" is configured (or not
unconfigured) where is shouldn't be.

(For the record, I agree with you on blocking ICMPs and blocking
.0/.255 ... both are bad ideas.  But so is forcing vendors to violate
the router requirements RFC.  If we (the internet community) want
directed broadcasts to be dropped by default, we should get off our
collective duffs and change the RFC.)


          - Brett  (brettf at netcom.com)
 
------------------------------------------------------------------------------
                               ... Coming soon to a      | Brett Frankenberger
.sig near you ... a Humorous Quote ...                   | brettf at netcom.com
 



More information about the NANOG mailing list