On Sat, 3 May 2014 01:25:40 -0400, Garrett Wollman wrote:
 > <<On Sat, 3 May 2014 13:53:44 +1000 (EST), Ian Smith <[email protected]> 
 > said:
 > 
 > > I've always allowed frags, as per the example rulesets in rc.firewall.  
 > > I only recall seeing them on DNS responses from zen.spamhaus.org, where 
 > > I see plenty of these after a resetlog before the logging limit kicks 
 > > in.  I doubt I'd be getting rid of ~90% of incoming spam without; eg:
 > 
 > Blocking inbound fragments will definitely screw you when you try to
 > use DNSsec.

Thanks to you and Darren; more grist for mending the Handbook ipfw page, 
likely why some people have been perhaps ill-advisedly dropping frags.

cheers, Ian
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[email protected]"

Reply via email to