From owner-freebsd-security Tue Jan 18 12:50:34 2000 Delivered-To: freebsd-security@freebsd.org Received: from phoenix.volant.org (phoenix.volant.org [205.179.79.193]) by hub.freebsd.org (Postfix) with ESMTP id 4EDE615065 for ; Tue, 18 Jan 2000 12:50:24 -0800 (PST) (envelope-from patl@phoenix.volant.org) Received: from asimov.phoenix.volant.org ([205.179.79.65]) by phoenix.volant.org with esmtp (Exim 1.92 #8) id 12AfZx-0004Mc-00; Tue, 18 Jan 2000 12:50:17 -0800 Received: from localhost (localhost [127.0.0.1]) by asimov.phoenix.volant.org (8.9.1b+Sun/8.9.1) with SMTP id MAA10312; Tue, 18 Jan 2000 12:50:15 -0800 (PST) Date: Tue, 18 Jan 2000 12:50:15 -0800 (PST) From: patl@phoenix.volant.org Reply-To: patl@phoenix.volant.org Subject: Re: TCP/IP To: David Wolfskill Cc: matt@ARPA.MAIL.NET, freebsd-security@freebsd.org In-Reply-To: <200001181917.LAA76938@pau-amma.whistle.com> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; CHARSET=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On 18-Jan-00 at 11:21, David Wolfskill (dhw@whistle.com) wrote: > >Date: Tue, 18 Jan 2000 12:53:12 -0500 > >From: matt > > >I would love to talk my uplink (uunet.ca) into filtering certain things > >before they pass it on to my router, wish they would =/ Besides that, I > >filter syn,fin, icmp, all udp except ntp/dns, besides that, I don't think > >there is much that I can do. > > Put another router in series with it. Use an RFC 1918 "private net" > numbering scheme for that (pathological) network, which then becomes an > effective "demarc" between uunet.ca's responsibility/ability and yours. > > This generalizes, within reason. (Yes, it adds latency, too....) Umm, I think Matt's point was that he would like to filter these things out -before- they consume bandwidth between his uplink and his router. (I know I would...) -Pat To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message