[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Host-based may be the way to go, but network controls are neccessary



   Agree. However, addressspace and preventing DDOS are two completely
   different issues.

=> this is not 100% true: with the 2^64 addresses per link of IPv6,
you open the door to "in prefix" source spoofing, i.e., DDoS,
which defeats ingress filtering (look at the 3041 considered harmful
about the detailed argument).

The ip direct-broadcast problem is also in this way a addressing problem. I think it's not. It's an implementation issue. We create knobs for reasons, but we need to be careful with what we define as the default.


- kurtis -