|
|
|
|
|
by marshray
3479 days ago
|
|
Because effectively blocking packets at requires supervising all routes through which they might escape (i.e., managing a lot of dynamic rules on a lot of very critical routers), whereas injecting forged packets only requires one little box. Kinda like the Berlin Wall. Easier to shoot people attempting to cross than hermetically seal the entire border. |
|