[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: network controls are necessary



On Mon, 9 Dec 2002, Tony Li wrote:

> Oy.  I think the thought was that the routing system would detect the
> loss of connectivity via the locator and would send an ICMP unreachable,
> which would then trigger a switch to an alternate locator.

I'm slightly concerned about the security/DoS implications of allowing
unsolicited messages to vastly affect connectivity, even though some
topologies support the use of ingress filtering and unicast-RPF to
mitigate.

I'm also concerned with the network device having to send back all those
ICMP messages in response to active traffic in case of a major link
failing.

/cah

---
Craig A. Huegen, Chief Network Architect      C i s c o  S y s t e m s
IT Transport, Network Technology & Design           ||        ||
Cisco Systems, Inc., 400 East Tasman Drive          ||        ||
San Jose, CA  95134, (408) 526-8104                ||||      ||||
email: chuegen@cisco.com       CCIE #2100      ..:||||||:..:||||||:..