They could find out certain IP addresses I suppose from the routing tables, and presumably the access lists to determine what traffic is allowed into and out of the router network. Although access to their firewall ingress and egress rules would be more useful.
Egress Filtering
Description
Egress filtering is the practice of monitoring, controlling and restricting traffic leaving a network with the objective of ensuring that only legitimate traffic is allowed to leave and that unauthorised or malicious traffic is prevented from doing so.
Egress filtering is primarily achieved through the use of predefined security rules and policies implemented on the perimeter firewall, to block outbound traffic that uses protocols and destination ports that are unnecessary or subject to abuse. Network administrators are advised to ensure that appropriate measures are taken to prevent unauthorised access to the internet access router, as it is located outside the perimeter firewall, and if SNMP enabled, that apprioate measues are implemented to prevent it from being exploited.
While Egress filtering is not primarily focused on protecting one's own network, it does serve to protect the networks of other organisations, by preventing the spread of malware or traffic with a forged source (spoofed) IP address from leaving the network that has been compromised, either through the deliberate malicious activity of an individual user or the malicious activity caused by infections, botnets and other malware within the network
Ingress Filtering
Description
Ingress filtering is the practice of monitoring, controlling and restricting traffic entering a network with the objective of ensuring that only legitimate traffic is allowed to enter and that unauthorised or malicious traffic is prevented from doing so.
Ingress filtering is primarily achieved through the use of predefined security rules (e.g. packet filtering) and policies implemented on the perimeter firewall, to ensure that inbound traffic is from the network from which it claims to originate from. Network administrators are advised to ensure that appropriate measures are taken to prevent unauthorised access to the internet access router, as it is located outside the perimeter firewall, and if SNMP enabled, that apprioate measues are implemented to prevent it from being exploited.
Ingress filtering is a simple and effective method to limit the impact of a Denial of Service (DoS) attack, by denying traffic with a forged source (spoofed) IP address access to the network, and to help ensure that traffic is traceable to its correct network.