Re: Clever firewall rules

From: Chris Ricker (kaboom@gatech.edu)
Date: 09/17/01


Date: Sun, 16 Sep 2001 22:57:09 -0600 (MDT)
From: Chris Ricker <kaboom@gatech.edu>
To: <focus-linux@securityfocus.com>
Subject: Re: Clever firewall rules
Message-ID: <Pine.LNX.4.33.0109162252170.1528-100000@verdande.oobleck.net>

On Sun, 16 Sep 2001, Ross Vandegrift wrote:

> Modern kernels don't use this - they allow you set thresholds with
> regard to IP defragmentation. Chec /proc/sys/net/ipv4/ipfrag*.
>
> Unfortunately, a search of the internet for correct setings yeilded
> little information - that was a few months ago. I do, for some reason,
> think that the defaults are reasonable though... I would like
> someone with better understanding to substantiate or refute. And an
> explanation wouldn't be bad either ::-)

Check Documentation/networking/ip-sysctl.txt in the kernel src tree. The
explanations there seem fairly straight-forward:

IP Fragmentation:

ipfrag_high_thresh - INTEGER
        Maximum memory used to reassemble IP fragments. When
        ipfrag_high_thresh bytes of memory is allocated for this purpose,
        the fragment handler will toss packets until ipfrag_low_thresh
        is reached.

ipfrag_low_thresh - INTEGER
        See ipfrag_high_thresh

ipfrag_time - INTEGER
        Time in seconds to keep an IP fragment in memory.

later,
chris



Relevant Pages

  • Re: US spells out plan to bomb Iran
    ... As for Iraq, that was one reason, "a" reason, for invading them, but ... Iran is building a nuclear warhead factory and striving for ICBMs. ... And the current "attempt" is to avoid a war with Iran, ... The internet is international. ...
    (soc.culture.iraq)
  • Re: US spells out plan to bomb Iran
    ... As for Iraq, that was one reason, "a" reason, for invading them, but ... Iran is building a nuclear warhead factory and striving for ICBMs. ... And the current "attempt" is to avoid a war with Iran, ... The internet is international. ...
    (soc.culture.iraq)
  • Re: mail confusion
    ... If the hosts are on a network which is connected to the ... even if you're not going to use it on the Internet. ... > A simple reason is the sheer number of LANs with an internet connection ... Well, there are idiots everywhere. ...
    (Fedora)
  • Re: RANT: Why Sun is losing to Linux
    ... about trying to get the replacement for said piece of hardware to work. ... Hence the reason Linux is encroaching on Suns territory. ... hardware would result in that person avoiding all Sun solutions. ...
    (comp.sys.sun.admin)
  • Re: Backups HELP!
    ... I have rerun the backup wizard many times, ... Warning: Unable to open "C:\Documents and Settings\Administrator\Local ... Settings\Temporary Internet Files\Content.IE5\desktop.ini" - skipped. ... Reason: Access is denied. ...
    (microsoft.public.windows.server.sbs)