it's here

Eric Brandwine ericb at UU.NET
Tue Feb 12 19:32:07 UTC 2002


>>>>> "sd" == Sean Donelan <sean at donelan.com> writes:

sd> On Tue, 12 Feb 2002, Alex Rubenstein wrote:
>> http://www.cert.org/advisories/CA-2002-03.html

sd> ASN.1 is pretty cool, but I've been wondering are there that
sd> many ISPs which allow external SNMP access to their equipment?
sd> SNMP is a UDP management protocol, and even under the best of
sd> conditions, accepting packets from out of the blue isn't a good
sd> idea.

Spoofed packets?

It's not feasible to filter antispoof at OC-12 or OC-48 line rate on
all customer facing interfaces.

ericb
-- 
Eric Brandwine     |  To assert that the earth revolves around the sun is as
UUNetwork Security |  erroneous as to claim that Jesus was not born of a
ericb at uu.net       |  virgin.
+1 703 886 6038    |      - Cardinal Bellarmine (during the
Key fingerprint = 3A39 2C2F D5A0 FC7C  5F60 4118 A84A BD5D  59D7 4E3E



More information about the NANOG mailing list