Home page logo

nanog logo nanog mailing list archives

Re: Open Resolver Problems
From: "Dobbins, Roland" <rdobbins () arbor net>
Date: Mon, 1 Apr 2013 16:50:30 +0000

On Apr 1, 2013, at 11:18 PM, Patrick W. Gilmore wrote:

Of course, since users shouldn't be using off-net name servers anyway, this isn't really a problem! :)


It's easy enough to construct ACLs to restrict the broadband consumer access networks from doing so.  Additional egress 
filtering would catch any reflected attacks, per your previous comments.

Roland Dobbins <rdobbins () arbor net> // <http://www.arbornetworks.com>

          Luck is the residue of opportunity and design.

                       -- John Milton

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]