Proper Port Forwarding

Simon simon at optinet.com
Wed Jun 6 18:31:27 UTC 2012


Hi,

Can someone suggest an alternative/proper way to port forward using ipfw. Right
now I have the following and some bad clients cause too many FIN_WAIT_2 state

fwd IP,PORT2 tcp from any to me dst-port PORT1 keep-state

This easily causes DoS for when too many FIN_WAIT_2 are created and IPFW
stops forwarding using the rule above because of "too many dynamic rules"

Thanks,
Simon




More information about the freebsd-questions mailing list