Date: Fri, 02 May 2014 11:50:16 +0200 From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= <des@des.no> To: Mike Tancsa <mike@sentex.net> Cc: freebsd-security@freebsd.org Subject: Re: FreeBSD Security Advisory FreeBSD-SA-14:08.tcp Message-ID: <86y4ykik6f.fsf@nine.des.no> In-Reply-To: <53610127.5000603@sentex.net> (Mike Tancsa's message of "Wed, 30 Apr 2014 09:56:55 -0400") References: <201404300435.s3U4ZAw1093717@freefall.freebsd.org> <53610127.5000603@sentex.net>
next in thread | previous in thread | raw e-mail | index | archive | help
Mike Tancsa <mike@sentex.net> writes: > Is [scrub in all] the only pf option that will work, or is scrub > fragment reassemble sufficient ? "fragment reassemble" is implicit, but if you leave out "in" it will also scrub outgoing traffic, which is wasteful. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?86y4ykik6f.fsf>