* Rob [2007-10-24 00:05]:
well, it is valid. the parser is morepermissive than what we document.
> (http://www.openbsd.org/faq/pf/filter.html). If the rule wasn't being
hell no! if the rule can't be parsed correctly, pfctl throws an error
of course!
> block in log quick proto tcp port ssh keep state \
no. src-conn-rate works w/ established tcp conns, AFTER the 3whs, thus
making spoofing unfeasible. that info, of course, is in the manpage...
very loud and clear. why don't you check there before spreading fud on
the list? this doesn't only comply to you, but is completely beyond me.
why dowe invest lots of time and nerves and whatnot in manpages when
people do not read them, and instead guess a bit and then spread shit
because the guess was of course wrong? read the damn manpages!
--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| James Bottomley | Re: Announce: Linux-next (Or Andrew's dream :-)) |
| Trent Piepho | Re: [PATCH] fakephp: Allocate PCI resources before adding the device |
| Antonio Almeida | HTB accuracy for high speed |
| David Miller | [GIT]: Networking |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
git: | |
