Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 9 May 1995 12:26:09 +0200
From:      "Retal" <lirandb@netvision.net.il>
To:        <freebsd-security@freebsd.org>
Subject:   Some Kernel options
Message-ID:  <002601ba1df7$4da07940$b88f39d5@a>

next in thread | raw e-mail | index | archive | help
This is a multi-part message in MIME format.

------=_NextPart_000_0023_01BA1E08.10F6EEA0
Content-Type: text/plain;
	charset="windows-1255"
Content-Transfer-Encoding: quoted-printable

I could not have wondered but..Its only me or other people compiling =
their kernel with this options:
options         KBD_INSTALL_CDEV        # install a CDEV entry in /dev
options         TCP_DROP_SYNFIN         #drop TCP packets with SYN+FIN
options         TCP_RESTRICT_RST        #restrict emission of TCP RST
options         ICMP_BANDLIM                                             =
     =20

Those options has any effect? i use them for months but i havent seen =
any difference between my other machines.

BTW: if i add TCP_DROP_SYNFIN, it should effect setup option in my =
firewall ?if it is, how ?

Thanks,


-Liran Dahan- [lirandb@netvision.net.il]


------=_NextPart_000_0023_01BA1E08.10F6EEA0
Content-Type: text/html;
	charset="windows-1255"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Dwindows-1255" =
http-equiv=3DContent-Type>
<META content=3D"MSHTML 5.00.2919.6307" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>
<DIV><FONT face=3DArial size=3D2>I could not have wondered but..Its only =
me or other=20
people compiling their kernel with this options:</FONT></DIV>
<DIV><FONT face=3DArial=20
size=3D2>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
KBD_INSTALL_CDEV&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; # install a =
CDEV=20
entry in /dev<BR>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =

TCP_DROP_SYNFIN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #drop =
TCP=20
packets with =
SYN+FIN<BR>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
TCP_RESTRICT_RST&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #restrict =
emission of=20
TCP RST<BR>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
ICMP_BANDLIM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;=20
</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Those options has any effect? i use =
them for months=20
but i havent seen any difference between my other machines.</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV>BTW: if i add TCP_DROP_SYNFIN, it should effect setup option in my =
firewall=20
?if it is, how ?</DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Thanks,</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>-Liran Dahan- [<A=20
href=3D"mailto:lirandb@netvision.net.il]">lirandb@netvision.net.il]</A></=
FONT></DIV>
<DIV>&nbsp;</DIV></FONT></DIV></BODY></HTML>

------=_NextPart_000_0023_01BA1E08.10F6EEA0--


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?002601ba1df7$4da07940$b88f39d5>