North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: no ip forged-source-address

  • From: Petri Helenius
  • Date: Wed Oct 30 17:08:34 2002

> decides to attack, it would use some neighbor's IP.  The subnet I am on is
> a /24 and there very well may be a few dozen hosts.  I could be real
> sneaky and alter my IP randomly to be any of my neighbors for every packet
> I send out.
> 
This gets a lot sneakier when you got your /64 on the subnet. Specially 
if people start to build significantly larger subnets by default.

Pete