> OTOH, anybody who truly cares about security is blocking _all_ IP
> options at their border router, long before the packet is seen by any
> firewall.
Thereby breaking any number of useful things that can be done with
things like timestamp options.
If you really care about security, use bloody decent OSes so that you
don't flippin' *need* to block IP options, you don't *need* a firewall!
Options are there because they're useful and support valuable
facilities. Block 'em if you like, but you'll get no sympathy from
*me* when something breaks for you as a result.
der Mouse
[EMAIL PROTECTED]
7D C8 61 52 5D E7 2D 39 4E F1 31 3E E8 B3 27 4B