High throughput bgp links using gentoo + stipped kernel

Matt Palmer mpalmer at hezmatt.org
Mon May 20 21:45:58 UTC 2013


On Sun, May 19, 2013 at 04:42:23PM -0700, Seth Mattinen wrote:
> On 5/19/13 4:27 PM, Ben wrote:
> > Do you actually need stateful filtering?  A lot of people seem to think
> > that it's important, when really they're accomplishing little from it,
> > you can block ports etc without it.
> 
> I believe PCI compliance requires it, other things like it probably do too.

There'd be very few PCI compliant sites if PCI required stateful firewalling
in core routers.

- Matt




More information about the NANOG mailing list