[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: I-D ACTION:draft-savola-v6ops-6to4-security-01.txt




Fred L. Templin wrote:


Maybe I'm behind the times here, but when I last looked at DDoS
attacks randomly varying the IPv4 source address was an element
that made the attacks particularly difficult to trace. At that
time, it was not necessarily true that all sites in the global
IPv4 Internet properly configured IPv4 ingress filtering. Are
you saying this is no longer the case?
Some ISPs do ingress filtering, some don't.
The issue here is to make sure 6to4 will not be used
as a way to bypass ingress filtering when/if in place.

   - Alain.