Re: WG status 2003/08/13

John Kristoff <[email protected]> Wed, 13 Aug 2003 16:30:57 -0500
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
On Wed, 13 Aug 2003 15:24:14 -0400
"Leech, Marcus (EXCHANGE:FITZ:8M86)" <[email protected]> wrote:

> It would be useful to get the perspective of providers on this--if
> they aren't
>   adopting ingress/egress filtering, why would they adopt itrace?

If it means resources are going to be consumed (e.g. CPU) they are often
going to leave it disabled.  Even when some things may seem to have a
fairly insignificant impact, many things do not get enabled for this
reason.

If by filtering you mean not only anti-spoofing, but also protocol/port
filtering, providers will often only do so as a last resort.  Generally
the reason not to filter revolves around either a philosophical "we're
not the Internet firewall" argument or because there is a fear of
breaking some customer's valid apps, which may affect a provider's
business.

It'll be adopted if its easy, enabled by default and doesn't cause any
additional strain on network operations.  The last point raises an
additional barrier.  If i-trace generates calls to a NOC, where
customers are asking "what is this ICMP stuff you're sending me?", they
may be tempted to disable it to avoid the phone calls.

John