RE: This is a must read document. It will freak you out



  Not just ISPs.  Even if you think you've hardened every host inside 
your perimeter, egress filtering is a Good Thing.

David Gillett


On 8 Jun 2001, at 8:49, Graham, Randy (RAW) wrote:

> > Cessna, Michael [mailto:MCessna@rtm.com] wrote:
> >
> >[snip]
> >
> > Is it not reasonable to ask that an ISP ensures that the packets
> originating on it's network are from a source ip on it's network?
> >[snippage]
> 
> Totally reasonable.  Many on this list have said the same thing over and
> over.  Unfortunately, it appears that ISPs don't listen to our good advice.
> 
> 
> >[snip]
> > Michael Cessna
> 
> Randy Graham
> --
> You're kind of trying to pick between "horible disaster" and "attrocious
> disaster"  -- Paul D. Robertson (on VNC vs. PPTP)
> http://www.theregister.co.uk/content/2/19442.html - Mankind's greatest
> invention? 
> -
> [To unsubscribe, send mail to majordomo@lists.gnac.net with
> "unsubscribe firewalls" in the body of the message.]
> 


-
[To unsubscribe, send mail to majordomo@lists.gnac.net with
"unsubscribe firewalls" in the body of the message.]



questions/problems with archive to: webmaster@mcabee.org
Mail converted by MHonArc 2.4.7