[c-nsp] Filtering TCP NULL packets

Roland Dobbins rdobbins at cisco.com
Mon Jul 23 11:38:39 EDT 2007


On Jul 23, 2007, at 7:19 AM, Jim Devane wrote:

> What other methods might be more effective?

Identify the sources and use S/RTBH, if your platform(s) support uRPF  
(keeping in mind the attackers might be spoofing the sources).

-----------------------------------------------------------------------
Roland Dobbins <rdobbins at cisco.com> // 408.527.6376 voice

        Culture eats strategy for breakfast.

                -- Ford Motor Company





More information about the cisco-nsp mailing list