How do you put a TV station on the Mbone?

Antonio Querubin tony at
Thu May 5 16:26:48 UTC 2011

On Wed, 4 May 2011, George Bonser wrote:

>> SSM with encryption?
> Well, certainly, but source address can be very easily spoofed with a
> UDP multicast stream.  Now that could be mitigated with a lot of network
> configuration rules but something is needed that just works without all
> that.

It's harder to effectively use spoofed source addresses in multicasting 
because of RPF.  When you couple it with SSM you're forcing the attacker 
to either use multiple injection points, or gain access to a router close 
to the real source address.  Couple that with encryption and you're 
denying spoofed addresses as an effective intrusion venue for large groups 
of viewers listening to a specific SSM source.

Perfect is the enemy of good.

Antonio Querubin
e-mail:  tony at
xmpp:  antonioquerubin at

More information about the NANOG mailing list