[c-nsp] Handling the inbound ACL's with dynamic pd ipv6 prefix from the ISP

Dobbins, Roland rdobbins at arbor.net
Sun Dec 5 20:30:01 EST 2010


On Dec 6, 2010, at 12:10 AM, George Manousakis wrote:

>  You natted what was necessary to the specific host and you were fine.

NATting servers is always contraindicated due to the DoS danger the additional state represents. 

-----------------------------------------------------------------------
Roland Dobbins <rdobbins at arbor.net> // <http://www.arbornetworks.com>

 	       Sell your computer and buy a guitar.







More information about the cisco-nsp mailing list