Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: source routing and Ascend P50
From: Gary Wong/Ascend/US <Gary_Wong @ ascend . com>
Date: 2 Jul 96 6:22:20
To: Full Name Field <wall @ readybox . com>
Cc: firewalls <firewalls @ GreatCircle . COM>

Frank :

The filter rules are as below :

Input Filter 1 :
Generic...
Forward = No
Offset = 34
Length = 1
Mask = FF00000000000000
Value = 8300000000000000   #loose source route
Compare = Equals
More = No

Input Filter 1 :
Generic...
Forward = No
Offset = 34
Length = 1
Mask = FF00000000000000
Value = 8900000000000000   #strict source route
Compare = Equals
More = No

These filters will discard incoming packets with sourece route 
option.(ex:traceroute -g or traceroute -G)

Gary Wong
Ascend Communications Inc.

-------------------------------------------------------------------------------------------------------------





	wall @ readybox.com (Full Name Field) 
06/30/96 10:14 AM
To: firewalls @ GreatCircle.COM @ Internet
cc:  
Subject: source routing and Ascend P50


I have an Ascend Pipeline 50 router and would like to kill all
incoming source-routed packets.

   1) Is it possible to filter source-routed packets with a P50?

   2) If so, can anyone provide an example of such a filter rule?

I've spent some time on the phone with Ascend in an attempt to
answer these questions.  In that hunt, I spoke with four support
people, none of whom were familiar with the concept of source
routing.  (That was, in itself, a little disturbing.)  I tried to
explain what source routing was and why it was of interest, but I
never did get any useful responses.

---------------------------
Frank McCormick <gfm @
 readybox .
 com>





Indexed By Date Previous: Reading news via a firewall
From: gunni @ if . is (Gunnar Ingvi Thorisson)
Next: Training???
From: David Tate <dtate @ on . com>
Indexed By Thread Previous: RE: Reading news via a firewall
From: ken @ bridge . com
Next: Training???
From: David Tate <dtate @ on . com>

Google
 
Search Internet Search www.greatcircle.com