ICMP_BANDLIM and TCP_DROP_SYNFIN ?!

Vahric MUHTARYAN vahric at doruk.net.tr
Tue Nov 25 06:45:19 PST 2003


Hi Everybody 

	I red ipfw documents and I saw that "TCP_DROP_SYNFIN is not
recommended for web server" no any explanation about it ?! Do you have
any idea for why ?! 

	ICMP_BANDLIM in documents ; "Enable icmp error response bandwith
limiting . This will protect from D.O.S. packets attacks" --> Does it
means all type of ICMP attacks ?! or another thing if I drope all icmp
traffic Do I need to use it ?! 


	Vahric   



More information about the freebsd-questions mailing list