> > >(If you do this, ICMPs sourced by the remote router will send their > > >packets with an RFC1918 source address, which is strictly not allowed. > > >If you filter those packets, you'll break traceroute and PMTUd). > > > > I find that to be OK. :) > > Breaking PMTUd is OK? Thanks very much.
We block RFC1918 source addresses at our borders. This is not negotiable. If it breaks PMTUd because some operator used 1918 addresses on links, too bad... Steinar Haug, Nethelp consulting, [email protected] _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
