On Tue, Jan 06, 2004 at 05:31:41PM +0100, Cedric Berger wrote: > Henning Brauer wrote: > >On Tue, Jan 06, 2004 at 10:05:58AM +0100, Cedric Berger wrote: > >>Henning Brauer wrote: > >>>that is in practice true for 99% of you. > >>> > >>>the state key does not include the interface, but the direction. > >>>as long as routes do not change that is equivalent to beeing bound to > >>>the interface. > >>Yes, for "normal" (i.e. not spoofed) packets. > >og cedric, please stop that, this is horribly misleading. > >you don't get your packet in on the wrong interface until you match > >the state, and that requires a _lot_ of information (match the > >sequence number window, for example), taht makes it close to > >impossible. > Not all the word is TCP. > I took IKE as an example, since it: > - Uses UDP (therefore no sequence number) > - Use highly predictable source/destination ports (500/500). > > And the other protocols that can be passed "keep state" do not > even have a port...
it is still everything but easy to spoof packets onto an extsing connection. don't make stuff worse than it was; it wasn't. > >it's certainly neat that we can bind states to interfaces now, but it > >is not as if the previous behaviour is a problem. > I said "it will protect *a bit* better against spoofed packets." > Not: what was before was utterly wrong well it sounded like that
