Hello,

I am not sure if anyone would ever deploy such mechanism.

For contents it's useless as they have to filter DDoSes before they
reach their network.
For carriers is poorly scalable as they'd have to configure thousands
of prefixes.
It could make sense for eyeballs but they hardly would drop all the
traffic from their customers even if they're participating in a DDoS
(also note that inbound customer traffic is rarely an issue for
eyeballs)

Regards

On Tue, Nov 1, 2016 at 5:15 PM, Nick Hilliard <[email protected]> wrote:
> Sriram, Kotikalapudi (Fed) wrote:
>> This work has been submitted to OPSEC WG.
>> Posting here also since it may be of interest to GROW WG members as well.
>> Comments/suggestions on this draft are welcome -- here or on the OPSEC list.
>> Thank you.
>
> Sriram,
>
> this looks difficult to implement and easy to spoof.  urpf is already
> hard enough to implement in hardware and my understanding is that it
> usually requires either packet recirculation for the SAV process or else
> a separate source address lookup per packet.  If this lookup process is
> tied into other validation mechanisms which aren't available in the
> forwarding engine (e.g. common source ASN, etc), then there would be a
> requirement to punt packets, which is not viable.
>
> Could you explain how feasible urpf can avoid this situation?
>
> Nick
>
> _______________________________________________
> GROW mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/grow



-- 
Marco

_______________________________________________
GROW mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/grow

Reply via email to