Re: New iTrace proposal
Mikael Olsson <[email protected]> Fri, 17 Oct 2003 20:47:31 +0200
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
First out: the WG is officially dead. I doubt (though this isn't=20 really for me to say) that the cleaned-up (experimental!) RFC will=20 contain anything of material value that isn't already in it. Tomasz Grabowski wrote: >=20 > So, mode 1 (generate iTrace messages, don't forward any others iTrace > messages) is designed for [nincompoops]. Mandating such a mode means that suddenly all routers need to=20 apply ACLish behavior on all traffic. This was unlikely in the first place, and even less likely now. > their network *can't* be flooded with iTrace messages=20 No, but their internet connection can. > Pekka Savola wrote: > > I think just using the TTL=3D255 when originating packets should be e= nough. >=20 > TTL can be easily spoofed. There need to be a way to check if particula= r > iTrace messages was sent by particular router. You're missing the point. If I receive a packet with TTL 252, I know for a fact that it was generated by a host no more than three hops out. This is undeniable. Using this logic, you can reconstruct itrace chains with a "fair" degree of probability. This was the=20 essence of the original itrace proposal. --=20 Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 =D6RNSK=D6LDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com