Re: Fwd: I-D ACTION:draft-huitema-multi6-addr-selection-00.txt
David Gethings <[email protected]> Wed, 20 Oct 2004 15:21:10 +0100
| Newsgroups | gmane.ietf.multi6 |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday 19 October 2004 16:38, marcelo bagnulo braun wrote: > Comments are welcome Overall a good draft. But I do have one concern. In section 5.2 you propose 3 source address selection methods. The third suggests that a host try with all possible source addresses simultaneously that are within scope. While this offers the advantage of providing best path selection - as you point out in your draft - it could also provides a ready made DOS'ing mechanism. The DOS'er simply has to clear the SA cache and send a packet, cira repeat. My apologies if this security consideration is already addressed in another RFC/ID. Cheers Dg