question for TCP gurus (in ipfw)

Julian Elischer julian at elischer.org
Thu Dec 14 11:33:38 PST 2006


Alexander Motin wrote:
> Julian Elischer wrote:
>> could we do either of:
>> 1/ not set the ACK bit  and just not do the extra work. Just send a 
>> reset?
> 
> Reset packet MUST have valid sequence number. Else it will be rejected 
> as protection from DoS atack.

Andre's reference explains it very well...  thanks..


More information about the freebsd-net mailing list