Re: IPSEC VPNs capable of handling worm traffic

2003-11-21 Thread Petri Helenius
Daniel Golding wrote: All of these cute references to vendor c and vendor n go by the wayside when we slip and say Nortel or refer to CEF. :) IMHO, if you aren't breaking an NDA, you might as well name names. If you are breaking an NDA, using initials won't screen you from legal jeopardy... I

Re: IPSEC VPNs capable of handling worm traffic

2003-11-20 Thread Charlie Clemmer
On Thu, 20 Nov 2003 00:27:20 +0100, Magnus Eriksson wrote Will it help to throw a bigger box at the problem? Would help to know what box you're using if you want to know whether a larger box would help. -- This message has been scanned for viruses and dangerous content by MailScanner, and is

Re: IPSEC VPNs capable of handling worm traffic

2003-11-20 Thread Daniel Golding
All of these cute references to vendor c and vendor n go by the wayside when we slip and say Nortel or refer to CEF. :) IMHO, if you aren't breaking an NDA, you might as well name names. If you are breaking an NDA, using initials won't screen you from legal jeopardy... - Daniel Golding On

Re: IPSEC VPNs capable of handling worm traffic

2003-11-20 Thread Bruce R. Babcock
At 06:27 PM 11/19/2003, Magnus Eriksson wrote: The last 2 days I've been fighting against the Nachi ICMP onslaght on a customer network. Have you tried rate-limiting or blocking ICMP echo/echo/reply messages? Worm traffic will typically follow the default route to the FW for prefixes that are

IPSEC VPNs capable of handling worm traffic

2003-11-19 Thread Magnus Eriksson
The last 2 days I've been fighting against the Nachi ICMP onslaght on a customer network. Problem is that the random destination traffic seem to kill my VPNs by vendor N. CPU is consumed, probably due to trying to maintain/update route cache. Or maybe it hits it's pps limit. Ordinary traffic

Re: IPSEC VPNs capable of handling worm traffic

2003-11-19 Thread Greg Maxwell
On Thu, 20 Nov 2003, Magnus Eriksson wrote: The last 2 days I've been fighting against the Nachi ICMP onslaght on a customer network. Problem is that the random destination traffic seem to kill my VPNs by vendor N. CPU is consumed, probably due to trying to maintain/update route cache. Or