Re: New iTrace proposal

Mikael Olsson <[email protected]> Fri, 17 Oct 2003 23:51:04 +0200
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>

Tomasz Grabowski wrote:
>=20
> On Fri, 17 Oct 2003, Mikael Olsson wrote:
>=20
> > > So, mode 1 (generate iTrace messages, don't forward any others iTra=
ce
> > > messages) is designed for [nincompoops].
> >
> > Mandating such a mode means that suddenly all routers need to
> > apply ACLish behavior on all traffic.  This was unlikely in
> > the first place, and even less likely now.
>=20
> Why? Because of routers performance overheat? What is the reason?

You hit the nail on the head.  Routers and switches are rated=20
according to what they can _forward_, not what they can pass up to=20
the main CPU.

Not everything is a PC.


> > > their network *can't* be flooded with iTrace messages
> >
> > No, but their internet connection can.
>=20
> True. But they can keep theirs internal network immune to such attacks.
> Better than nothing, I think.

This is why we have network firewalls.


> And it's making iTrace as attractive to attackers as other blocked
> protocols.

And I still think you're accomplishing nothing by having
random edge routers block itrace. =20

What is your specific attack scenario?  -- Please remember that
people without firewalls are susceptible to any kind of flood,
from GRE to 123/UDP to ping to whatever have you.  Also remember
that the Internet connection usually dies from overload long
before your internal LAN even _begins_ to slow down.


--=20
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 =D6RNSK=D6LDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com