Great Circle Associates Firewalls
(January 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Source Routing and Disabling
From: Paul Ferguson <pferguso @ cisco . com>
Date: Tue, 02 Jan 1996 13:08:22 -0500
To: Ray Hooker <rayhook @ ibm . net>
Cc: "'Firewall Mailing List'" <firewalls @ GreatCircle . COM>

A common application for loose source-routing, used mainly by service 
providers, is troubleshooting routing problems in the Internet. It can
be quite helpful to trace a route *from* a specified node, *to* a
specified node.

Of course, this doesn't mean that you should allow loose source-routed
traffic into your internal network from external sources, however,
many service providers allow source-routed traffic transit on their
backbones for specifically this purpose.

- paul


At 12:01 PM 1/2/96 -0500, Ray Hooker wrote:

>I know certain things about source routing:
>  - Stated purpose (see RFC 791) was to allow the specification of routing
>    information to be used by gateways.
>  - I know how to code source routed packets under UNIX (or Linux).
>  - They can be used in attacking TCP/IP hosts (see IPEXT paper on
>    weaknesses in the TCP/IP protocol.
>  - Microsoft's tracert module purportedly has an option to use 
>    loose source-routing to debug network problems (this is their
>    version of traceroute).
>  - Some networks configure their routers to reject source-routed packets.
>  - Firewalls should reject source-routed packets.
>What I am curious about is what functions or applications, if any, commonly
use source-routing.  I haven't noticed any Telnet clients that, for example,
could specify a loose source-routing to contact a particular host.  I have
searched the Comer series on Internetworking with TCP/IP and other
references, but see little information on actual usage.
>
>Ray Hooker, rayhook @
 ibm .
 net
>Secure I/T Inc.
>1-919-544-4565
>

--
Paul Ferguson                                           ||        ||
Consulting Engineering                                  ||        ||
Reston, Virginia   USA                                 ||||      ||||
tel: +1.703.716.9538                               ..:||||||:..:||||||:..
e-mail: pferguso @
 cisco .
 com                         c i s c o S y s t e m s


Indexed By Date Previous: ipx-bridging & ip-routing
From: Pablo <pablo @ smartlink . net>
Next: Compression is useful - but for security, not
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Indexed By Thread Previous: Re: Source Routing and Disabling
From: JOSE LUIS VERDEGUER NAVARRO <a01056 @ eps . ua . es>
Next: ipx-bridging & ip-routing
From: Pablo <pablo @ smartlink . net>

Google
 
Search Internet Search www.greatcircle.com