North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: engineering --> ddos and flooding

  • From: Joel Jaeggli
  • Date: Thu May 31 21:23:59 2001

On Thu, 31 May 2001 [email protected] wrote:
>
> Why should it be so great deal? It should allow me only to add filters on
> the traffic that is destined to me, not arbitrary filters...
>

Filters have a non-zero impact on cpu overhead. Where they end up in the
forwarding path could negativly affect your upstream or other routers in a
fashion that's signficantly worse than the attack on you affects them...

The potential for someone at isp B to do engineering on the way that
traffic from isp A's customers flow to isp B on isp A's routers ought to
be fairly disturbing to most folks. Normally that's something that both
parties have to agree on first.