Update to RFC2669 (Resend)
Shahram Esfahani <[email protected]>
| Newsgroups | gmane.ietf.ipcdn |
|---|---|
| Message-ID | <[email protected]> |
Hi folks, I never got a response for anyone so I am resending my question/comments. In light of the recent virus/worm attacks on cable subscribers, has the IETF considered updating RFC2669 to include rate-limiting? Many MSOs combated the network impacts of the virus/worm infections by configuring ACLs on their CMTS. However, the traffic characteristics of these infected users reveled numerous ICMP echo requests being sent upstream -- in the magnitude of hundreds per second. Having just a few infected users in a MAC domain can put unnecessary stress on the CMTS to issue grants and flood the domain with ARP requests. A better solution to these CMTS-centric ACLs would be to rate-limit this type of traffic on the cable modem. Rate-limiting can also be applied to other traffic besides ICMP. For example, some MSOs have expressed concerns about very aggressive IP stacks sending DHCP packets too quickly causing server strain. Your thoughts about this? Thanks and regards, Shahram