In message <234661D0.3000@usr.com>, Pat Calhoun writes:
Alexis,
However if you are filtering on your outbound router to the net, there is still the possbility that a malicious user could spoof addresses as long as they belong to your address space. By moving the filter out to the edge (when you have the equipment) this eliminates that problem as well.
Pat R. Calhoun e-mail: pcalhoun@usr.com Project Engineer - Lan Access R&D phone: (847) 933-5181 US Robotics Access Corp.
Know what ISP the traffic is coming from is enormously useful compared to "its coming from NSP X" or worse yet, "its coming from someone on Mae-East". That's often were we start from these days. Curtis