From owner-freebsd-security Sat Jan 22 3:29:27 2000 Delivered-To: freebsd-security@freebsd.org Received: from critter.freebsd.dk (critter.freebsd.dk [212.242.40.131]) by hub.freebsd.org (Postfix) with ESMTP id BFB6815772 for ; Sat, 22 Jan 2000 03:29:23 -0800 (PST) (envelope-from phk@critter.freebsd.dk) Received: from critter.freebsd.dk (localhost.freebsd.dk [127.0.0.1]) by critter.freebsd.dk (8.9.3/8.9.3) with ESMTP id MAA12130; Sat, 22 Jan 2000 12:29:05 +0100 (CET) (envelope-from phk@critter.freebsd.dk) To: "Dan Seafeldt, AZ.COM System Administrator" Cc: sthaug@nethelp.no, gdonl@tsc.tdk.com, security@FreeBSD.ORG Subject: Re: MAPS effort / CISCO 12.0 In-reply-to: Your message of "Sat, 22 Jan 2000 03:22:31 PST." Date: Sat, 22 Jan 2000 12:29:05 +0100 Message-ID: <12128.948540545@critter.freebsd.dk> From: Poul-Henning Kamp Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org In message , "Dan Seafel dt, AZ.COM System Administrator" writes: > >I have a CISCO router upgraded to pre-release 12.0 and will look at that. >And regarding the mention of MAPS effort, I thought about that but I was >worried about all the ISP's out there who may use one >gateway/router to connect 2 separate upstream netblocks without any use of >BGP. In this case, it is possible that outbound packets will always go >through one upstream ISP even though the returns end up going through 2 >different ISP's For example, a CISCO 2600 series with one Frame Relay >connection and 2 PVCS to two different upsteams, and the gateway set to one >of these PVC's with a different class C coming down each PVC's > >I could see where an egress block enabled by the upstream provider who is >not the gateway would shut down access to that class C. Not all ISP's can >afford to or understand how to implement BGP but want some amount of >redudancy or additional bandwidth via 2 different upstreams. You know, that would be the most lame excuse for not doing anything about this I have heard so far. That ISP, can still put egress filters on both their outgoing PVCs as long as they allow both C classes both ways. But I would be terribly disappointed if their upstream didn't block all but their assigned C class in. -- Poul-Henning Kamp FreeBSD coreteam member phk@FreeBSD.ORG "Real hackers run -current on their laptop." FreeBSD -- It will take a long time before progress goes too far! To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message