Re: serious flaw exposed via filters (fwd)
Krzysztof Adamski (kadamski@bob.netsurf.net)
Tue, 17 Sep 1996 08:09:51 -0400 (EDT)
One way to eliminate the routing loop is to put a filter on your wan port.
An outgoing filter can deny any packet that has a destination address of
your network.
Also everybody should have an incomming filter that denys everything with
source that has your networks address.
If you only have the second one then a packet will make a trip
through the wan port to the outside router and then back just once.
Krzysztof