haven't made up my mind on that - either the routers directly connecting to the Internet or closer into my "core". Rogelio wrote: > matthew zeier wrote: >> Trying to find a pre-build set of ACLs for filtering bogus inbound >> udp, if one already exists, otherwise I'll have to build my own :) > > Where are you trying to filter this? At your CPE router?