North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: DoS attacks, NSPs unresponsiveness

  • From: Valdis.Kletnieks
  • Date: Thu Nov 02 10:37:07 2000

On Thu, 02 Nov 2000 09:59:04 EST, Mark Mentovai <mark-list@mentovai.com>  said:
> This can't go on forever.  I'd like to spread the clue about ingress
> filtering, and am willing to commit time to the cause.  Is anyone with me?

The problem is that for many ISPs, I fear the only way to get them to
implement 2827-style filtering is for their upstreams to implement a
policy of fascist-mode ingress filtering - "We see a bogon packet that
your site should have filtered, we pull the plug on your link till you
fix it".

Time alone won't be enough.  Bring a baseball bat.  And a spare bat.

-- 
				Valdis Kletnieks
				Operating Systems Analyst
				Virginia Tech


Attachment: pgp00000.pgp
Description: PGP signature