Re: SYN flooding....

Matthias Urlichs (smurf@work.smurf.noris.de)
30 May 1997 16:53:03 +0200


Craig Brozefsky <craig@onshore.com> writes:
>
> UUnet in Chicago does no filtering either. I was able to shoot packets
> of any design up that pipe. I suppose for them filtering at the more
> central routers is akin to making a high speed runner doing marathon
> stints present a report to the Environmental Protection Agency regading
> the consequences of each of his footfalls for each step.
>
Filtering by source address is no more expensive than routing by
destination address, assuming that the downstream site doesn't have another
internet connection. In both cases, you look it up in the routing table.

-- 
Seize the day, put no trust in the morrow!
               --Quintus Horatius Flaccus (Horace)
-- 
Matthias Urlichs         \  noris network GmbH  /  Xlink-POP Nürnberg 
Schleiermacherstraße 12   \   Linux+Internet   /   EMail: urlichs@noris.de
90491 Nürnberg (Germany)   \    Consulting+Programming+Networking+etc'ing
   PGP: 1024/4F578875   1B 89 E2 1C 43 EA 80 44  15 D2 29 CF C6 C7 E0 DE
       Click <A HREF="http://info.noris.de/~smurf/finger">here</A>.    42