Filtering Source Addresses on gw-internet

One of the IS group Engineers ran some tests in the lab.
(Thanks Craig). It appears that, unfortunately, policy routing
packets to Null0 is also a process switched operation.
Apparently Null0 does not qualify as a Point-to-point interface
with regards to the Set Interface command.

GK

I vaguely remember hearing somewhere that routing to a loopback interface
was better than null0 for feeding unwanted packets into a black hole. Is
that case perhaps not process switched?

jlewis@inorganic5.fdt.net (Jon Lewis) writes:

I vaguely remember hearing somewhere that routing to a loopback interface
was better than null0 for feeding unwanted packets into a black hole. Is
that case perhaps not process switched?

Nope, sorry. Also process switched.

The hack to drop things fast is to find a lightly loaded LAN interface and
then forward it all to a non-existant system on that LAN. Of course,
you'll have to manually configure an ARP entry for the bogon.

Tony