: (1) I'm using keep state, not synproxy. Is PF still attempting to do
: window sequence space comparisons and dropping packets if they do
: not match? If it is, do you know where in the code that is
: (I've been staring at it a while trying to find just such a
: comparison but not having a whole lot of luck).
Wait, I think I found it. I think the DROP is handled by the else
clause around line 4030 of pf.c (in the DragonFly code). I'm not
entirely sure.
It looks like it will be easy to flag state creation without a SYN
and have it ignore sequence space comparisons for that case.
-Matt| debian developer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg Kroah-Hartman | [PATCH 002/196] Chinese: rephrase English introduction in HOWTO |
| Linus Torvalds | Re: Long delay in resume from RAM (Was Re: [patch 00/69] -stablereview) |
| Parag Warudkar | BUG: soft lockup - CPU#1 stuck for 15s! [swapper:0] |
git: | |
| Andi Kleen | [PATCH RFC] [4/9] modpost: Fix format string warnings |
| Rick Jones | Re: Network latency regressions from 2.6.22 to 2.6.29 |
| Antonio Almeida | HTB accuracy for high speed |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
