On Monday 07 April 2008 01:48:28 Matthew Dillon wrote:Right. See the attached forward from the pf mailinglist. The referenced paper is a good read, too. Yes, if you also flush states. Usually you won't drop active states. You'd simply time them out more aggressively (see adaptive.{start,end} in pf.conf(5) if your version has that already) or not allow a new state to be created. It really depends on what you want to achieve. If you are after security for a network of clients with bad/broken TCP stacks then leaving out the window checks is not a good idea. I can see that there are cases where you'd want to check only the (src,dst,proto)-tuple and pass every matching packet regardless. Currently pf doesn't allow for this to happen statefully and I don't think OpenBSD is going to make that change, ever. If you think of pf as a security first and foremost mechanism this makes sense. I'm also somewhat reluctant to make that change in FreeBSD, otoh there are cases where you'd want that rope. -- /"\ Best regards, | mlaier@freebsd.org \ / Max Laier | ICQ #67774661 X http://pf4freebsd.love2party.net/ | mlaier@EFnet / \ ASCII Ribbon Campaign | Against HTML Mail and News
| Ingo Molnar | Re: [BUG] long freezes on thinkpad t60 |
| Rafael J. Wysocki | Re: [Bug 10030] Suspend doesn't work when SD card is inserted |
| Jamie Lokier | Proposal for "proper" durable fsync() and fdatasync() |
| jimmy bahuleyan | Re: how about mutual compatibility between Linux's GPLv2 and GPLv3? |
git: | |
| Martin Langhoff | Handling large files with GIT |
| Matt Mackall | Re: cleaner/better zlib sources? |
| Wink Saville | git-svn segmetation fault |
| Bill Lear | Meaning of "fatal: protocol error: bad line length character"? |
| Florin Andrei | firewall is very slow, something's wrong |
| Wijnand Wiersma | Almost success: OpenBSD on Xen |
| Marcus Andree | Re: OpenBSD kernel janitors |
| Richard Stallman | Real men don't attack straw men |
| David Miller | Re: tcp bw in 2.6 |
| Rick Jones | Re: 2.6.24 BUG: soft lockup - CPU#X |
| Patrick McHardy | [NET_SCHED 00/04]: External SFQ classifiers/flow classifier |
| Patrick McHardy | Re: [PATCH 2/2] [e1000 VLAN] Disable vlan hw accel when promiscuous mode |
