[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: network controls are necessary
On Mon, 9 Dec 2002, Tony Li wrote:
> Oy. I think the thought was that the routing system would detect the
> loss of connectivity via the locator and would send an ICMP unreachable,
> which would then trigger a switch to an alternate locator.
I'm slightly concerned about the security/DoS implications of allowing
unsolicited messages to vastly affect connectivity, even though some
topologies support the use of ingress filtering and unicast-RPF to
mitigate.
I'm also concerned with the network device having to send back all those
ICMP messages in response to active traffic in case of a major link
failing.
/cah
---
Craig A. Huegen, Chief Network Architect C i s c o S y s t e m s
IT Transport, Network Technology & Design || ||
Cisco Systems, Inc., 400 East Tasman Drive || ||
San Jose, CA 95134, (408) 526-8104 |||| ||||
email: chuegen@cisco.com CCIE #2100 ..:||||||:..:||||||:..