4 ms·
You mean "egress", and that's only helpful in cases where the source is in fact spoofed. With a large and widely distributed number of small devices, there isn
by dgemm 10y ago
You mean "egress", and that's only helpful in cases where the source is in fact spoofed. With a large and widely distributed number of small devices, there isn't much of a need.
- Animats 10y agoIf the IP address isn't spoofed, you can block by IP at intermediate points, firewall, attack the attacker, or get the responsible ISP to turn the connection off. Random IPs are a much bigger headache. As for the ingress/egress thing, the RFC calls it ingress filtering. Not worth arguing over.