Re: [c-nsp] Hardening LPTS
Saku Ytti <[email protected]>
| Newsgroups | gmane.network.nsp.cisco |
|---|---|
| Message-ID | <CAAeewD9yEr9ZNcGC=wQO3Gd1UOxVS003S7U+9DEWDMxf8mDSvQ@mail.gmail.com> |
On Fri, 4 Jun 2021 at 17:19, Mark Smith <[email protected]> wrote: > Thanks for comments. This is very valuable info. What are your thoughts about: > flow udp default rate 0 > flow tcp default rate 0 > > Are they safe to use? Cisco did not recommend them but I dont understand why. And they failed to explain. Maybe because they dont understand themselves either As LPTS is never going to be particularly safe for attackers but mostly will work for accidental congestion I would personally not change anything, until you have realised risk, at least then I will have some confidence that the change improves availability. -- ++ytti _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/