Re: Land and Cisco question

From: Joe Shaw (no email)
Date: Sun Nov 23 1997 - 10:17:56 EST


On Sun, 23 Nov 1997, Alan Barrett wrote:

> Randy Bush said:
> > for each interface on a router
> > block tcp which is both to and from that interface
>
> I don't think that's sufficient. What about spoofed packets arriving via
> interface A, with IP source and destination both set to the address of
> interface B?
>
> --apb (Alan Barrett)

no ip source-route should fix it.

Joe Shaw -
NetAdmin - Insync Internet Services
Up WAY too early on a Sunday... :)








Hosted Email Solutions

Invaluement Anti-Spam DNSBLs



Powered By FreeBSD   Powered By FreeBSD