On Thu, 9 Nov 2006, Stephane Bortzmeyer wrote: > > While I agree that the text need not necessarily be so absolute, I > > would not consider [such] ingress filtering proper or wide-scale > > deployment. Better than nothing, to be sure, but not enough. > > May be but it does not seem that BCP 38, lauded as the Ultimate and > Everlasting solution to Everything, strongly warns the ISP about > that. It seems it contains no discussion or advice about the best > place to put the antispoofing filters. (Some examples or sentences > mention filters which are close to the customer, some do not.)
Which is why I referred to BCP84/RFC3704, which _does_ include this discussion. -- Pekka Savola "You each name yourselves king, yet the Netcore Oy kingdom bleeds." Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings . dnsop resources:_____________________________________________________ web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html
