On Wednesday, August 25, 2010 05:15:43 am Gert Doering wrote: > I don't really want to start a heated debate on whether > topology hiding is good or bad -
I guess that ship has sailed :-). > but it comes with some > consequences :-) We prefer not to hide our topology. Granted, for customer VPN's, we tend to implement l2vpn's over l3vpn's for obvious reasons. But since a number of our customers are ISP's, and we know a bunch of users have some clue re: traceroutes, MTR, e.t.c., we try not to make their lives hard by hiding the network topology. Any determined attacker can always find ways to get into your network if it's weak. We'd rather focus energies on implementing secure router configurations, good operational practices and proper change management, rather than relying on obscurity :-). But, YMMV :-). Mark.
signature.asc
Description: This is a digitally signed message part.
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
