BCP38/84 and DDoS ACLs

Randy Bush randy at psg.com
Fri May 26 23:07:57 UTC 2017


to be honest, i do not block chargen etc at my borders; i scan hosts
and turn off silly services on the hosts.  but i do not have myriads of
hosts in a soft gooey inside.

what i block at my borders are 135-139, 161 (except for holes for
measurement stations), 445, 514, stuff such as that.

ykmv

randy



More information about the NANOG mailing list