Other possible protection against RST/SYN attacks (was Re: TCP RST attack

Gary Corcoran garycor at comcast.net
Wed Apr 21 15:10:22 PDT 2004


> In any event, it still seems like a TTL of 255 is overkill for this application...

Unless, of course, you want to only accept packets with TTL
of 255.  This might be fine when both ends are setup to work
this way.  But it might break general interoperability...

Gary





More information about the freebsd-security mailing list