Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IP spoofing
From: SOBRIEN @ MAIL . STATE . WI . US
Date: Fri, 20 Sep 1996 13:17:06 -0500
To: "firewalls(a)GreatCircle.COM" <firewalls @ GreatCircle . COM>
X400-content-type: P2-1988 (22)
X400-mts-identifier: [/PRMD=WISTGOV/ADMD=ATTMAIL/C=US/;0003800005632168000004]
X400-originator: SOBRIEN @ MAIL . STATE . WI . US
X400-recipients: firewalls @ GreatCircle . COM


I'm by no means an expert, and I'm not even sure I'd say I'm knowledgable
about this topic.  But I'm spitting out my 2 cents worth anyway. :-)

>        I'm afraid that I wasn't too clear on what my confusion is.  I
>actually did understand why the filter wouldn't prevent SYN attacks.  my
>confusion was the statement in the CERT of "With the current IP protocol
>technology, it is impossible to eliminate IP-spoofed packets.". Implying
>that you can't stop IP-spoofing totally.

Wouldn't having all routers filter out packets with a source ip outside the
routers net severly limit ip spoofing?  Wouldn't this require using valid ip
addresses from within the routers *realm*.   You could spoof an address but
it would have to be valid for the router to pass it on.

>        I think what I am being told is that this packet filtering would
>prevent any packets spoofed to your own internal net address, but would not
>be able to prevent spoofs of someone else's address from coming in.

I think your correct here.

>I'm not
>sure what the implications of the other addresses being spoofed would be to
>my network security, unless I am allowing a trusted access of sorts.
>        Maybe that's naive?  Any other comments?

Well one implication is a SYN attack.

Sean

Indexed By Date Previous: Re: Netscape ?
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Next: Re: IP spoofing
From: Brian Harvell <harvell @ inet . net>
Indexed By Thread Previous: Re: IP spoofing
From: "Tracy R. Reed" <treed @ straylight . connectnet . com>
Next: Re: IP spoofing
From: Lyndon David <lyndond @ sentinet . co . uk>

Google
 
Search Internet Search www.greatcircle.com