Garrett Wollman wrote:

<<On Sun, 03 Jul 2005 00:06:37 +0200, Jesper Wallin <[EMAIL PROTECTED]> said:

First of all, I know that not dropping SYN/FIN isn't really a big deal, it
just makes no sense. But since it doesn't make any sense, I don't see
the reason why not to discard them.

Perhaps because you are under the erroneous impression that such
packets are nonsensical.

-GAWollman

That might be the case yeah.. Yet, if I have TCP_DROP_SYNFIN in my kernel and sysctrl net.inet.tcp.drop_synfin set to 1, shouldn't it drop all SYN/FIN packets no
matter how my firewall is configured?

Best regards,
Jesper Wallin
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to