Re: packets with syn/fin vs pf_norm.c

From: Darren Reed (avalon_at_caligula.anu.edu.au)
Date: 07/06/05

  • Next message: fooler: "Re: packets with syn/fin vs pf_norm.c"
    To: rcoleman@criticalmagic.com (Richard Coleman)
    Date: Wed, 6 Jul 2005 13:56:38 +1000 (Australia/ACT)
    
    

    In some mail from Richard Coleman, sie said:
    > 1. I thought that T/TCP was being removed from FreeBSD (already happened?).
    > 2. It's trivial to predict Theo's response to this.
    > 3. Since T/TCP is rare, there is little motivation to alter scrub to
    > function differently than OpenBSD with respect to these packets. If
    > someone really needs this, there are plenty of alternatives.

    I didn't know about (1) but I'd agree with (2) and (3).

    > But more importantly, the original question has been lost. The original
    > question was what should the various firewalls do when the kernel has
    > been compiled with TCP_DROP_SYNFIN. Regardless of whether those packets
    > are valid or not, a person may have reason to compile this feature into
    > the kernel. So, should the firewalls acts differently if this kernel
    > option is used?

    IMHO, No.

    Darren
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: fooler: "Re: packets with syn/fin vs pf_norm.c"

    Relevant Pages

    • Re: reiser4 plugins
      ... > Hans Reiser wrote: ... >> There has been no response to the technical email asking for what ... > because of the kernel cabal .. ... "Because our code is 90% library routines (aka plugins), ...
      (Linux-Kernel)
    • Re: [BUG] New Kernel Bugs
      ... the form [Bug 1234] so that bugzilla will capture the discussion. ... One response from a developer ... Kernel: 2.6.24-rc2 ... Zero responses from developers ...
      (Linux-Kernel)
    • KERNEL 2.6.3 and MAXTOR 160 GB
      ... the kernel 2.6.1 or 2.6.3 does not. ... ACPI: No IRQ known for interrupt pin A of device 0000:00:04.0 - using IRQ ... no response, ... hdd: no response, ...
      (Linux-Kernel)
    • Re: KDE 3.4.1 + X.org 6.8.2 + GeForce MX 4400 + nVidia modules = freeze... but not always!
      ... I forgot to mention that my kernel is the one from Debian Sid ... > It does sound like permission problems. ... process is it and to know what kind of response is it waiting for). ...
      (comp.windows.x.kde)
    • Re: Not to whine, but [more details on NIC problem]
      ... William's response to my e-mail. ... show up when I installed the SMP version of the 2.6 kernel with a SuSE ... It is indeed a 3com card. ... The computer can see the network through the card, ...
      (Fedora)