On Fri, Apr 07, 2000 at 10:27:57AM +1000, Marty wrote:
> Yeah, but you can be DoS'd with this if someone spoofs a scan from say the
> root dns servers, or your ISP's mail server etc. You can feed IP addresses
> to NMAP for spoofed scans... a quick script and you could end up with a very
> broken ipchains ruleset.

Agree completely. Automated firewalling is the quickest way to breakage ...

> Optus wants to preserve its backchannel bandwidth. What happens if one has a
> cable modem connection and a permanent dialup (to some other ISP)? ie,
> inbound requests come via the dialup, but the replies go out via the
> cable... not hard to setup with ip-masq and a few pc's, and no open ports
> for Optus to find on the cable connection... asymmetric routes used to break
> things occasionally (vague recollection of being burned by this years ago) -
> any guesses at what might break under a setup like this?

Not much, usually. A good ISP (i.e. your dialup) will not allow you to generate
packets for addresses which you have not been assigned or are not supposed to
appear on whatever allocation range you are in. This helps prevent spoofing.

When I last checked, sometime in 1997, there were no ISPs which did this.
Likely this has changed ...

Anand
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to