option 1 is the ideal...but firewall bozo's don't want to change, they want this resolved on the router.
with option 3, would a route of 172.16.0.0/12 to null0 mean anything 172.16.0.0 thru 172.31.0.0 would get blackholed? Unless I use all of the /12 I would still get loops on the subnets...
simple question, my default route on my core points to the firewall. The firewall has static routes stating that 172.16.0.0 in on the inside interface (which it is).
when I traceroute to a non-valid 172.16.0.0 IP, I get a loop between my core and the firewall.
Now the question, who should...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.