Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 18 Jan 2000 11:17:45 -0800 (PST)
From:      David Wolfskill <dhw@whistle.com>
To:        matt@ARPA.MAIL.NET
Cc:        freebsd-security@freebsd.org
Subject:   Re: TCP/IP
Message-ID:  <200001181917.LAA76938@pau-amma.whistle.com>
In-Reply-To: <Pine.BSF.4.21.0001181252220.98451-100000@w01.arpa-canada.net>

next in thread | previous in thread | raw e-mail | index | archive | help
>Date: Tue, 18 Jan 2000 12:53:12 -0500
>From: matt <matt@ARPA.MAIL.NET>

>I would love to talk my uplink (uunet.ca) into filtering certain things
>before they pass it on to my router, wish they would =/ Besides that, I
>filter syn,fin, icmp, all udp except ntp/dns, besides that, I don't think
>there is much that I can do.

Put another router in series with it.  Use an RFC 1918 "private net"
numbering scheme for that (pathological) network, which then becomes an
effective "demarc" between uunet.ca's responsibility/ability and yours.

This generalizes, within reason.  (Yes, it adds latency, too....)

Cheers,
david
-- 
David Wolfskill		dhw@whistle.com		UNIX System Administrator
voice: (650) 577-7158	pager: (888) 347-0197	FAX: (650) 372-5915


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200001181917.LAA76938>