On Maw, 2005-07-12 at 05:05, shogunx wrote: > > Verifying source is fairly hard except for internal network traffic. > > Perhaps a quick arp lookup on the ip address indicated in the packets, and > a comparison to the originating mac address's ip. Who would that exclude? > Forged ip addresses. Virtual hosts, in some instances.
Anything behind a router and anything not with differing in and out routing paths. Anything being load balanced over multiple cables..... ---------------------------------------------------------------------- For LINUX-390 subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit http://www.marist.edu/htbin/wlvindex?LINUX-390
