Re: NetReg: No default route for unknown clients

New Message Reply Date view Thread view Subject view Author view Attachment view

From: Florian Weimer (fw@deneb.enyo.de)
Date: Sat May 22 2004 - 03:45:41 CDT


* Robert Lowe:

> Yes, but remember that security by obscurity is no security at all.
> It is common practice for the IP address space used by unregistered
> clients to be filtered at some border router, for example, such that
> Internet access is prevented.

If you set the default route in the pre-authentication stage, all
those Windows worms will spew traffic into the network, up until the
filter. If the filter is behind a choke point, your access network is
in danger of collapsing under the load. People observe this effect
with WLAN configurations and certain subscriber gateways.

-- 
Current mail filters: many dial-up/DSL/cable modem hosts, and the
following domains: bigpond.com, di-ve.com, hotmail.com, jumpy.it,
libero.it, netscape.net, postino.it, simplesnet.pt, spymac.com,
tatanova.com, tiscali.co.uk, tiscali.cz, tiscali.it, voila.fr, yahoo.com.
**********************************************************************
To unsubscribe from this list, send an e-mail message to
majordomo@southwestern.edu containing a single line with the words:
unsubscribe netreg
Send requests for assistance to: owner-netreg@southwestern.edu
**********************************************************************

New Message Reply Date view Thread view Subject view Author view Attachment view

This archive was generated by hypermail 2.1.4 : Thu Aug 12 2004 - 12:01:45 CDT