>>>>> "M" == Marty  <[EMAIL PROTECTED]> writes:

    M> asymmetric routes used to break things
    M> occasionally (vague recollection of being burned by this years
    M> ago) - any guesses at what might break under a setup like this?

  Can't speak for Optus, but BPA do egress filtering. I'd be surprised 
if Optus didn't. You can't originate packets not from your own
assigned address - and you can't reply to requests sent to one IP with 
replies from another!

    M> Are they scanning from certain dedicated machines? Maybe we can
    M> just blackhole the route for those machines... tho ideally we'd
    M> want to send lots of RST's instead of nothing.

  Mmm - I run most services on the tunnel interface, in my
case, which means there's nothing for a portscan over my DHCP address
to find. Incoming services other than login tend not to be latency 
sensitive, so it works fine for things like mail - but traceroute to
eris.rcpt.to to see how bad a latency hit it is. The last hop is a
tunnel from my bedroom to California...

m.
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to