[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [FW1] VRRP multicasts
Hmmm... Nokia's marketing documentation basically says you can do away with a border router and have this wonderful integrated IP box that does all. It is very capable, agreed, but I certainly don't want VRRP multicasts being broadcast to my upstream provider. I'll make sure I set some good authentication up on the VRRP interfaces when I get round to it so these multicasts, if intercepted, cannot provide a way in to DoS my firewall ! (I meant VRRP, not BTTP in my original post - my fingers missed...) Tim ----- Original Message ----- From: Nils Kolstein <[email protected]> To: 'Tim Holman' <[email protected]>; <[email protected]> Sent: 13 April 2001 08:42 Subject: RE: [FW1] VRRP multicasts > Hi, > > I guess you have to block the multicast traffic on the ACL's on the > routers.. Using the fail-over cable is irrelevant as the multicasts are > distributed on the segment/VLAN in which the monitored circuit interfaces > are resident. > > Hope this helps.. > > Nils Kolstein > Internetworking Engineer > Planet Media Group > E-mail: [email protected] > Tel.: (+31)> > > -----Original Message----- > > From: Tim Holman [mailto:[email protected]] > > Sent: Wednesday, April 11, 2001 8:28 PM > > To: [email protected] > > Subject: [FW1] VRRP multicasts > > > > > > > > I've setup 2x Nokia IP440s using monitored circuits. > > I now want to prevent VRRP multicasts from being broadcast upstream. > > As I have a failover cable between the two machines, is it > > possible to > > restrict BTTP to that cable only, or do I have to filter out > > the multicasts > > using border routers ? > > > > Tim > > ______________________________________________________________ > > ___________ > > Get Your Private, Free E-mail from MSN Hotmail at > > http://www.hotmail.com. > > > > > > > > ============================================================== > > ================== > > To unsubscribe from this mailing list, please see the > > instructions at > > http://www.checkpoint.com/services/mailing.html > > ============================================================== > > ================== > > > ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|