> Daniel Kosack writes:
> > Be sure that you drop source routed frames and source IP addresses;
> > they can be a real pain on a network. Most routers drop source routed
> > frames, but not source IPs.
> Huh? How do you drop source IP addresses? And why would you want to? It's a
> bit difficult to open a TCP connection if you don't know the address you're
> supposed to be handshaking with. Other transport-layer protocols also rely on
> the source IP address.
Note the distinction:
1) Source routed frames
2) Source IPs
Don't know what source routed traffic is? Read this document.
http://www.v-one.com/pubs/fw-faq/faq.htm
-Dan