My contention would be to let routers do what routers do
best, and to me antispoofing is a form of routing control. 
Let the firewall be a packet filter.  I do agree with lance
though, you must have some form of antispoofing or you will
be dead in the water.

***
From: Lance Spitzner [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, July 26, 2000 1:10 PM
To: Bryan Morris
Cc: [EMAIL PROTECTED]
Subject: Re: [FW1] Is there any reason not to use the
Anti-Spoofing
feature?



On Wed, 26 Jul 2000, Bryan Morris wrote:

> Is there any reason not to use the Anti-Spoofing feature on FW-1?


If you do NOT have Anti-Spoofing setup at your border, such
as 
the firewall or router, someone can most likely take out
your network.

ftp://ftp.technotronic.com/denial/

hope that helps,

lance
-- 
Paul Keefer             AMI-300B/NISC
LAN/WAN Administrator   405-954-6029


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to