On Wednesday, August 25, 2010 05:15:43 am Gert Doering 
wrote:

> I don't really want to start a heated debate on whether
> topology hiding is good or bad -

I guess that ship has sailed :-).

> but it comes with some
> consequences :-)

We prefer not to hide our topology. Granted, for customer 
VPN's, we tend to implement l2vpn's over l3vpn's for obvious 
reasons. But since a number of our customers are ISP's, and 
we know a bunch of users have some clue re: traceroutes, 
MTR, e.t.c., we try not to make their lives hard by hiding 
the network topology.

Any determined attacker can always find ways to get into 
your network if it's weak. We'd rather focus energies on 
implementing secure router configurations, good operational 
practices and proper change management, rather than relying 
on obscurity :-).

But, YMMV :-).

Mark.

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to