From owner-freebsd-isp@FreeBSD.ORG Sun Feb 10 12:48:59 2013 Return-Path: Delivered-To: freebsd-isp@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id 81517A96; Sun, 10 Feb 2013 12:48:59 +0000 (UTC) (envelope-from snabb@epipe.com) Received: from angkar.epipe.com (angkar.epipe.com [IPv6:2001:470:b:566::4]) by mx1.freebsd.org (Postfix) with ESMTP id 5D07EAAA; Sun, 10 Feb 2013 12:48:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=epipe.com; s=default; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:References:Subject:CC:To:MIME-Version:From:Date:Message-ID; bh=ZZCw0EkCYWBC8Ch2iX0c+C9hiuiJWQc0EQvyu3qYhTc=; b=O7s1onXJEkSyhjCAyj1d5C4WH835IIMasO3MwmhJgnmy+3JYhzLE9hqBb2VOUG1feOaGondBL3k2RheUIexG3AGgQT5q3RxMusoE7EGbbzU57gD2AGwaaK2tG0D9/LEo+XTA5+QwWO1oUyhuGcNwPlp3CcpTnF/WvdWsUU3uWvA=; Received: by angkar.epipe.com with esmtpsa (TLS1.0:DHE_RSA_CAMELLIA_256_CBC_SHA1:256) (Exim 4.80) (envelope-from ) id 1U4WL1-0002w2-7i; Sun, 10 Feb 2013 12:48:55 +0000 Message-ID: <51179708.2030206@epipe.com> Date: Sun, 10 Feb 2013 14:48:08 +0200 From: Janne Snabb MIME-Version: 1.0 To: khatfield@socllc.net Subject: Re: FreeBSD DDoS protection References: <321927899.767139.1360461430134@89b1b4b66ec741cb85480c78b68b8dce.nuevasync.com> In-Reply-To: <321927899.767139.1360461430134@89b1b4b66ec741cb85480c78b68b8dce.nuevasync.com> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: "freebsd-isp@freebsd.org" , "freebsd-security@freebsd.org" , James Howlett X-BeenThere: freebsd-isp@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: Internet Services Providers List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 10 Feb 2013 12:48:59 -0000 On 2013-02-10 03:57, khatfield@socllc.net wrote: > Deny all ICMP (drop I mean) and UDP except where specifically required. Please do not drop all ICMP unless you understand what you are doing. By doing that you are creating a path MTU discovery blackhole. See for example the following sites for more information: http://www.phildev.net/mss/ https://supportforums.cisco.com/docs/DOC-5839 http://www.cymru.com/Documents/icmp-messages.html http://packetlife.net/blog/2008/oct/09/disabling-unreachables-breaks-pmtud/ -- Janne Snabb / EPIPE Communications snabb@epipe.com - http://epipe.com/