Re: (PM) DoS attack

Jon Lewis (
Tue, 24 Feb 1998 01:13:24 -0500 (EST)

On Mon, 23 Feb 1998, David Denney wrote:

> On Saturday night my company fell victim to a DoS attack that completely
> sacked all three of our pipes (a T3 and two T1s). The resultant ethernet
> traffic made even our 100bTx local network unusable because of the
> attacker was flooding multiple portmasters on unreachable IP addresses.
> Every packet they sent bounced around our network until its TTL was
> reached. When is this disastrous behavior going to be fixed??

So put a filter on each PM saying that packets destined for addresses in
the assigned pool cannot leave via ether0.

Jon Lewis <> | Unsolicited commercial e-mail will
Network Administrator | be proof-read for $199/message.
Florida Digital Turnpike |
______ for PGP public key____

To unsubscribe, email '' with
'unsubscribe portmaster-users' in the body of the message.
Searchable list archive: <URL:>