On Thu, 22 Oct 2009 22:36:13 EDT, Jon Kibler said: > 4) Never allow traffic to ingress any network if the source address is > bogus.
4a) Never flag a source address as bogus unless you can verify it is bogus *today*, not when you installed the filter. Out of date bogon filters are evil.
pgpwJHR922JEm.pgp
Description: PGP signature