Re: [Freeipa-devel] [PATCH] 205 Remove UDP checks from conncheck

2012-02-27 Thread Martin Kosek
On Wed, 2012-02-01 at 17:55 +0100, Martin Kosek wrote: UDP port checks in ipa-replica-conncheck always returns OK even if they are closed by firewall. They cannot be reliably checked in the same way as TCP ports as there is no session management as in TCP protocol. We cannot guarantee a

[Freeipa-devel] [PATCH] 205 Remove UDP checks from conncheck

2012-02-01 Thread Martin Kosek
UDP port checks in ipa-replica-conncheck always returns OK even if they are closed by firewall. They cannot be reliably checked in the same way as TCP ports as there is no session management as in TCP protocol. We cannot guarantee a response on the checked side without our own echo server bound to