24 Mar
2017
24 Mar
'17
3:30 p.m.
* Laurent Dumont:
Wouldn't you want BCP38 policies to be as close as possible to the traffic sources? Instead of creating more "fake" traffic?
Maybe as close as possible, but still without sacrificing source network attribution is sufficient.
And at the same time, partial filtering doesn't seem as a very effective way to fight spoofed traffic on a large scale.
That depends on the problems caused by spoofed traffic. My hunch is that non-policing networks emit a constant trickle of spoofed traffic which does not cause any problems, and that traffic can be used to detect lack of policing even without actual abuse of the spoofing capability.