logoalt Hacker News

stackskiptonlast Tuesday at 2:41 PM2 repliesview on HN

One simple way to do it is configure the customers routers to drop/reject all UDP/TCP packets where SRC address does not match Private IP/WAN Assigned Public IP.


Replies

__turbobrew__last Tuesday at 3:15 PM

I cannot believe this is still not commonly done. I remember discussing this with some people in the industry over ten years ago and the sentiment was “if ISPs just stopped IP spoofing that would solve most problems”.

show 1 reply
Y_Ylast Tuesday at 3:12 PM

The customer's router is for the customer to configure

show 2 replies