On 05/08/16 16:35, Lukas Tribus wrote:
Not all packets cause the wedge. If your CoPP allows NTP from your
configured NTP servers, but not from others, you're fine.
Unless the IP address of your NTP servers are known to an attacker,
in that case the packet can simply be spoofed.
If you're not doing uRPF and ingress filtering of your own netblocks,
you've got bigger problems IMO
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/