Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Looping TRACERT?
From: Benedikt Stockebrand <benedikt @ devnull . ruhr . de>
Date: 28 Nov 1996 11:37:21 +0100
To: chrisp @ optimation . co . nz (Chris Palmer)
Cc: firewalls @ GreatCircle . COM
In-reply-to: chrisp @ optimation . co . nz's message of Thu, 28 Nov 1996 10:30:35 NZST
References: <199611271259 . HAA15008 @ homeport . org> <chrisp . 28 . 00467605 @ optimation . co . nz>

chrisp @
 optimation .
 co .
 nz (Chris Palmer) writes:

> For any (Cisco) routers that have a default route, I always setup static
> routes to Null0 for any nets that are normally directly connected. When the
> interface is up, the connected route overrides the null route. Easy way to
> stop traffic going out the default route when the proper one isn't there. Also
> works in various subnetting situations.
> (NB. I've only tried this with statically routed configs. I don't know what
> the implications might be when running various routing protocols!).

Done it with gated (running RIP-2) on both Linux (1.2.13) and FreeBSD
(2.1.0).  You add passive routes with a high metric to the down
interface (FreeBSD) or reject routes with high metric (Linux).  When
the real routes are up and have a lower metric, they are used instead.

Sorry I don't remember any more details, but it's more than a year ago
that I did it.  And I don't have any more access to those systems.


    Ben

-- 
Ben(edikt)? Stockebrand    Runaway ping.de Admin---Never Ever Trust Old Friends
My name and email address are not to be added to any list used for advertising
purposes.  Any sender of unsolicited advertisement e-mail to this address im-
plicitly agrees to pay a DM 500 fee to the recipient for proofreading services.


References:
Indexed By Date Previous: Re: How to secure a Webpage?
From: Craig McLellan <mclelcl @ onto . network . com>
Next: Re: How to secure a Webpage?
From: Bertrum Carroll <carrolls @ revealed . net>
Indexed By Thread Previous: Re: Looping TRACERT?
From: chrisp @ optimation . co . nz (Chris Palmer)
Next: Re: Looping TRACERT?
From: Paul Ferguson <pferguso @ cisco . com>

Google
 
Search Internet Search www.greatcircle.com