Great Circle Associates Firewalls
(February 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Supply-side spoofing prevention
From: btk @ matrix . cray . com (Bryan Koch)
Date: Thu, 2 Feb 95 8:55:09 CST
To: peterg @ airdata . com (Peter Gregory)
Cc: firewalls @ greatcircle . com
In-reply-to: <9502020019 . AA27190 @ dividivi>; from "Peter Gregory" at Feb 1, 95 4:19 pm

> Excellent point.  We're all concerned with INbound spoofing (because
> they harm US and represent a threat to US), but how many of us filter 
> OUTbound spoofing?
> 
> Probably damned few of us.  
> 
> I mean, who'd want to go to the extra trouble to complicate our access lists 
> with entries that do nothing to protect us and just slow down our routers?

We have always filtered outbound packets to ensure that they originate
on our assigned networks.

Bryan Koch
Cray Research


Follow-Ups:
References:
Indexed By Date Previous: re:IBM Firewall Solution
From: "Bai, Mario" <BAIM @ itg . viacom . com>
Next: Prevention of LOCAL spoofing/duplicate I
From: "Robertson, Paul" <proberts @ moc1 . gannett . com>
Indexed By Thread Previous: Supply-side spoofing prevention
From: peterg @ airdata . com (Peter Gregory)
Next: Re: Supply-side spoofing prevention
From: criney1 @ abacus . tis . tandy . com (Chris Riney)

Google
 
Search Internet Search www.greatcircle.com