Re: max-src-conn-rate rule question

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Wednesday, October 24, 2007 - 4:12 am

* Rob [2007-10-24 00:05]:

well, it is valid. the parser is morepermissive than what we document.

> (http://www.openbsd.org/faq/pf/filter.html). If the rule wasn't being

hell no! if the rule can't be parsed correctly, pfctl throws an error
of course!

> block in log quick proto tcp port ssh keep state \

no. src-conn-rate works w/ established tcp conns, AFTER the 3whs, thus
making spoofing unfeasible. that info, of course, is in the manpage...
very loud and clear. why don't you check there before spreading fud on
the list? this doesn't only comply to you, but is completely beyond me.
why dowe invest lots of time and nerves and whatnot in manpages when
people do not read them, and instead guess a bit and then spread shit
because the guess was of course wrong? read the damn manpages!

--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
max-src-conn-rate rule question, david l goodrich, (Sun Oct 21, 3:22 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 4:58 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 5:55 pm)
Re: max-src-conn-rate rule question, Henning Brauer, (Wed Oct 24, 4:12 am)
Re: max-src-conn-rate rule question, Rob, (Wed Oct 24, 8:26 am)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 8:30 pm)
Re: max-src-conn-rate rule question, Vijay Sankar, (Tue Oct 23, 10:36 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 8:59 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Wed Oct 24, 12:02 am)
Re: max-src-conn-rate rule question, Calomel, (Tue Oct 23, 5:46 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Wed Oct 24, 12:23 am)
Re: max-src-conn-rate rule question, Calomel, (Wed Oct 24, 11:40 am)