[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: impact of recent cisco vulnerability



Do you think it makes sense to post something on this to the MIPv4 list?
They are supposed to be talking about deployment considerations, and this
seems like a big one to me.

            jak

----- Original Message ----- 
From: <itojun@iijlab.net>
To: <iab@ietf.org>; <iesg@ietf.org>
Sent: Thursday, August 14, 2003 8:10 PM
Subject: Re: impact of recent cisco vulnerability


> > because of recent cisco vulnerability, many ISPs installed filters
> > that would drop mobile-ip4 (ip protocol type 55), both inbound and
> > outbound at EBGP routers, as a countermeasure until they upgrade all
> > of the cisco routers they have.  it would seriously impact the
> > deployment/use of mobile-ip4.
> >
> > also swipe (53), sun ND (77), PIM (103) are getting filtered.  i don't
> > think PIM operation will be affected by this as people wouldn't use
> > PIM across AS borders.  not sure about swipe and sun ND.
>
> more on this - some of the japanese ISPs decided to keep the ACL to
> drop them almost forever.  i.e. mobile-ip4 is dead.
>
> itojun
>
>