North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Martian list of IP's to block???

  • From: Jared Mauch
  • Date: Fri Oct 01 12:27:33 1999

On Fri, Oct 01, 1999 at 08:49:23AM -0700, [email protected] wrote:
> >     deny   ip 224.0.0.0 31.255.255.255 any log
>
> 	I'm not convinced that blocking native multicast is a good idea.

	This is blocking packets sourced with a multicast ip, not
destined for multicast.

	ex: when i source multicast traffic the src ip is the ip of
the machine sending the traffic, and the dst is the ip of the multicast
group.

	so traffic would go from (for example) puck.nether.net (204.42.254.5)
to the multicast group for Places all over the World (224.2.172.238).

	This acl would prevent someone from sending a ping to your 
router, and faking the src ip to be something like all-routers.mcast.net,
and having you start ping flooding all the multicast routers,
or multicast hosts out on the internet.  (Think semi smurf-attack like).

	- jared
	
-- 
Jared Mauch  | pgp key available via finger from [email protected]
clue++;      | http://puck.nether.net/~jared/  My statements are only mine.
END OF LINE  |