North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: ARIN to Allocate from

  • From: Kai Schlichting
  • Date: Wed Nov 10 12:10:22 1999

At 11:50 AM 11/10/99 -0500, Richard A Steenbergen <[email protected]> wrote:

>I might almost be happy, except this breaks the oh-so-nice filter of
> at borders (effectively reduces random src spoofed attacks
>by 25%, and covers as well). Go ARIN. </sarcasm>

One line becomes two in your ACL ? 
ip permit
ip deny 

The CPU loss for one more ACL line is probably offsetting the gains of
spoofed traffic pretty well. That will even scale for a little while,
at least for /9 and /10 in the permit line, before you seriously have
to think about how much still-unallocated space you will gratutiously allow
through your ACL.