From owner-freebsd-security Mon Dec 17 0:34:38 2001 Delivered-To: freebsd-security@freebsd.org Received: from noname.csdl.lt (noname.csdl.lt [194.176.40.182]) by hub.freebsd.org (Postfix) with SMTP id 28F3737B41E for ; Mon, 17 Dec 2001 00:34:34 -0800 (PST) Received: (qmail 97178 invoked by uid 1000); 17 Dec 2001 08:34:32 -0000 Date: Mon, 17 Dec 2001 10:34:32 +0200 From: Paulius Bulotas To: freebsd-security@FreeBSD.ORG Subject: Re: options TCP_DROP_SYNFIN Message-ID: <20011217083432.GA96883@noname> Mail-Followup-To: freebsd-security@FreeBSD.ORG References: <20011217073102.GA94480@noname> <20011217185456.A34365@raven.robbins.dropbear.id.au> Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline In-Reply-To: <20011217185456.A34365@raven.robbins.dropbear.id.au> User-Agent: Mutt/1.3.24i Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On 01 12 17, Tim J. Robbins wrote: > > Anyone can explain, why enabling this option is wrong on web server? > way handshake. I gather that it's more efficient if you have lots of > quick connects and disconnects as you do with HTTP when not using the > keepalive features. Ok, so I should disable keep alive in Apache and enable SYN+FIN (disable option ;), then I'll get faster connects.?. but how many clients (OSes) use this rfc? None? or they should be enabled somehow? Paulius To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message