[geeks] Fwd: [Incident 020324-000029] unroutable traffic being passed to my nameserver

alex j avriette avriettea at speakeasy.net
Fri Mar 29 17:55:32 CST 2002


>   I'd say this is a steaming crock of shit.  They *should* be filtering
> RFC1918 addresses anyway...on modern (and even not-so-modern) router
> hardware the performance impact is negligible.  If they're running any

yup, that was my guess.

>   Sounds to me like they just don't want to be bothered, or their
> routers are already overloaded and they don't want to spend the bucks
> to upgrade them.

i think speakeasy is blowing smoke up my ass, so i did send internap a 
message as well. i dont suppose anyone on-list knows anyone at 
noc at internap?

>   I don't know what your network looks like...Is it practical for you to
> filter them on your end?

I am filtering them. I have apparently pissed a few people off, and 
occasionally (1-2x a month) get a DDOS with 200-300 hosts attacking, 
most of which is from unroutable ip's. I'm using openbsd's pf, but my 
downstream is only 1.5mbit (1.5sdsl). The last time I got hit, the 
traffic across speakeasy's switch was 6.5mbit.

the network is basically dsl bridge -> openbsd pf/binat -> 
(( intranet )).

alex



More information about the geeks mailing list