SYN floods (was: does history repeat itself?)

Actually what Justin was talking about is as follows...

Justin will only allow packets out of his border routers /to/ peers if they
are packets with a source address inside the ranges of addresses he
announces via BGP. I.e. if I announce 192.1.1.0 0.0.0.255 I would allow a
packet with an address of 192.1.1.1 out of my network into "the net at
large" but not if the packets source address was 192.1.2.1. I will allow
any packet which I allow to enter my network into a customer's network.
Their filtering is their problem.

Justin Newton
Internet Architect
Erol's Internet Services