> > >(If you do this, ICMPs sourced by the remote router will send their
> > >packets with an RFC1918 source address, which is strictly not allowed.
> > >If you filter those packets, you'll break traceroute and PMTUd).
> > 
> > I find that to be OK.  :)
> 
> Breaking PMTUd is OK?  Thanks very much.

We block RFC1918 source addresses at our borders. This is not
negotiable. If it breaks PMTUd because some operator used 1918
addresses on links, too bad...

Steinar Haug, Nethelp consulting, [email protected]
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to