Burst
Ivo Vachkov
ivo at bsdmail.org
Sun Sep 7 04:13:45 PDT 2003
> the problem with your approach is that the user can easily overcome
> the limitation by splitting the connection into many small ones,
> each one below the allowed burst size.
Indeed this is not a problem since I track src_ip and dst_ip ... and not tcp/udp ports. So even if someone starts many connection to a single host for my code they're all same, i.e. counting the traffic through all of them as one.
--
_______________________________________________
Get your free email from http://mymail.bsdmail.com
Powered by Outblaze
More information about the freebsd-ipfw
mailing list