Re[4]: SYN floods (was: does history repeat itself?)

        If I understand what you are stating is that the filtering which I
     have described could work for dial-up users, but not for customers
     which have a dedicated "leased" line into the network. You state that
     this is not possible due to the CPU overhead that the filtering of
     each packet creates.
        Out of curiosity, what would the CPU usage be on a typical router
     in your installation??? Also, do we know what the overhead is for a
     single filter at the ingress on a router such as a Cisco???
