Tier 2 ingress filtering


On 3/29/13, Patrick <nanog at haller.ws> wrote:
> On 2013-03-29 14:49, William Herrin wrote:
>> I've long thought router vendors should introduce a configuration
>> option to specify the IP address from which ICMP errors are emitted
>> rather than taking the interface address from which the packet causing
>> the error was received.
> Concur. An 'ip(v6)? icmp source-interface loop0' sure beats running 'ip
> unnumbered loop0' everywhere. ;)

Why do you think it will be better?, can you explain?
So far I can only think in a more difficult troubleshooting if this
idea/feature gets spread.

I guess based in the scenario where the output interface can not reach
Internet sounds as a practical solution however for sure the output
interface is reachable inside the provider network.