Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Anyone have an idea what percentage of networks and hosting providers drop spoofed packets originating from inside their networks? What are the downsides of dropping them?


You're referring to BCP-38, aka RFC 2827. It's actually decently hard for a transit network to do this at scale. You can do it when you're a small ISP, but the administrative stuff becomes harder as you get larger and are constantly getting more allocations, buy out other ISP's, etc.

Every content network should do it. Not a huge win there, but it's something.

I'm not saying we shouldn't try, but there are countless, very long threads on NANOG about why some transit networks just can't do it.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: