Hi,

On Fri, Aug 05, 2016 at 11:02:01AM +0300, Saku Ytti wrote:
> I disappointed Cisco does not mention CoPP at all.
> 
> Anyone running reasonable CoPP would have been completely unaffected
> by this issue. CoPP is not just about protecting from DoS, it's also
> protecting from 0days.

Sure about that?

I'm not sure about *this* interface wedge bug, but if it's similar to the
original one, if your CoPP policer lets even 1% of the packets through,
you're still toast - just slower.  With NTP, of course you have permit
rules in your CoPP config, so depending on which NTP servers you talk
to, nastygrams can still arrive...

(OTOH if you have a CoPP rule that says "drop all that might be harmful",
I'm all ears)

gert

-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             [email protected]
fax: +49-89-35655025                        [email protected]

Attachment: signature.asc
Description: PGP signature

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to