Re: Re: Router filtering not enough! (Was: Re: CERT advisory )

Pete Hartman (pwh@bradley.bradley.edu)
Thu, 26 Jan 95 22:21:34 -0600

>But in real life, the spoofing machine would never be requested to respond
>to arp anyway, because in real life the spoofer should be on the other side
>of your firewall router.  If the spoofer and spoofee are on the same ether-
>net then there are serious internal problems that go beyond the scope of
>firewalls!!

But such problems are the stock-in-trade of those of us at Universities.