Burst

Ivo Vachkov ivo at bsdmail.org
Sun Sep 7 04:13:45 PDT 2003


> the problem with your approach is that the user can easily overcome
> the limitation by splitting the connection into many small ones,
> each one below the allowed burst size.

Indeed this is not a problem since I track src_ip and dst_ip ... and not tcp/udp ports. So even if someone starts many connection to a single host for my code they're all same, i.e. counting the traffic through all of them as one.


-- 
_______________________________________________
Get your free email from http://mymail.bsdmail.com

Powered by Outblaze


More information about the freebsd-ipfw mailing list