Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: IP spoofing
From: Andrea Brenton <abrenton @ hurwitz . com>
Date: Fri, 20 Sep 1996 10:00:06 -0400
To: Firewalls @ GreatCircle . COM

        I usually just hang out here trying to learn from all the great info
that gets posted here (Thanks all!), but I just got a CERT that I had to ask
some questions of the experts on.
        The CERT warns of SYN attacks (lots of traffic on that here lately),
and mentions IP spoofing.  The statement in the CERT is "With the current IP
protocol technology, it is impossible to eliminate IP-spoofed packets.
However, you can take steps to reduce the number of IP-spoofed packets
entering and exiting your network.  Currently, the best method is to install
a filtering router that restricts the input to your external interface
(known as an input filter) by not allowing a packet through if it has a
source address from your internal
network. "  
        I am not clear on why this would not eliminate IP-spoofed packets
all together.  Seems pretty straight forward to me.  Prevent any packets
coming into my network from the internet if they originate from an IP number
that applies to my internal network.  What would it miss?  What am I missing?
        Thanks for any clarification that might be offered!



xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Disclaimer:  Any errors in spelling, tact, or fact are transmission   
errors.

Andrea Brenton			Hurwitz Group, Inc
IS Manager			29 Crafts St
abrenton @
 hurwitz .
 com		Newton, MA  02158



Follow-Ups:
Indexed By Date Previous: Re: netra firewalls
From: David Strong <dstrong @ www . os . dhhs . gov>
Next: RE: Re[2]: FW: NT vs. UNIX white paper
From: jsluzewski @ dna . com
Indexed By Thread Previous: Re: Improving Solaris resistance to syn attacks
From: Karl Strickland <karl @ bagpuss . demon . co . uk>
Next: Re: IP spoofing
From: Jeff Thompson <jwthomp @ cu-online . com>

Google
 
Search Internet Search www.greatcircle.com