Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IP spoofing
From: Ian Miller <firewalls @ scientia . com>
Date: Mon, 23 Sep 1996 11:06:25 +0100
To: Firewalls @ greatcircle . com

At 08:19 20/09/96 -0700, Ken Jones <kenj @
 cayman .
 gblhorizon .
 com> wrote:
>We checked out both the CERT warning and the cisco web page. What
>they are advising is two things (in regaurd to packet filtering)
>
>1. Filter out IP spoofing for packets orignating at your site. Don't
>   let your users be the bad guy.
>
Excellent advice.  One minor implementation point.  Most filters don't
let you write a rule that will deny all traffic that is NOT to or from
a specific address.  What we do is limit all our permit rules to having our
class-C (or a subset) as source or destination as appropriate.  Then any
packet with an invalid source address is blocked by default deny.  

I don't know if a site failing to do this could be held liable for the
actions of a local bad guy.  However as it is entirely avoidable there seems
no point in taking the risk.

Ian


Indexed By Date Previous: Re: Subnet MasK
From: Paul Ferguson <pferguso @ cisco . com>
Next: Re: Source Routing
From: Thomas Lopatic <lopatic @ dbs . informatik . uni-muenchen . de>
Indexed By Thread Previous: Re: IP spoofing
From: Adam Shostack <adam @ homeport . org>
Next: Re: IP spoofing
From: "Jerry McKane" <jerrym @ Onramp . NET>

Google
 
Search Internet Search www.greatcircle.com