Re: New iTrace proposal
Mikael Olsson <[email protected]> Fri, 17 Oct 2003 23:51:04 +0200
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
Tomasz Grabowski wrote: >=20 > On Fri, 17 Oct 2003, Mikael Olsson wrote: >=20 > > > So, mode 1 (generate iTrace messages, don't forward any others iTra= ce > > > messages) is designed for [nincompoops]. > > > > Mandating such a mode means that suddenly all routers need to > > apply ACLish behavior on all traffic. This was unlikely in > > the first place, and even less likely now. >=20 > Why? Because of routers performance overheat? What is the reason? You hit the nail on the head. Routers and switches are rated=20 according to what they can _forward_, not what they can pass up to=20 the main CPU. Not everything is a PC. > > > their network *can't* be flooded with iTrace messages > > > > No, but their internet connection can. >=20 > True. But they can keep theirs internal network immune to such attacks. > Better than nothing, I think. This is why we have network firewalls. > And it's making iTrace as attractive to attackers as other blocked > protocols. And I still think you're accomplishing nothing by having random edge routers block itrace. =20 What is your specific attack scenario? -- Please remember that people without firewalls are susceptible to any kind of flood, from GRE to 123/UDP to ping to whatever have you. Also remember that the Internet connection usually dies from overload long before your internal LAN even _begins_ to slow down. --=20 Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 =D6RNSK=D6LDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com