Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 3 Apr 2015 14:27:30 +0300
From:      Gleb Smirnoff <glebius@FreeBSD.org>
To:        Hans Petter Selasky <hps@selasky.org>
Cc:        Mateusz Guzik <mjguzik@gmail.com>, Ian Lepore <ian@freebsd.org>, svn-src-all@freebsd.org, src-committers@freebsd.org, "Robert N. M. Watson" <rwatson@FreeBSD.org>, svn-src-head@freebsd.org
Subject:   Re: svn commit: r280971 - in head: contrib/ipfilter/tools share/man/man4 sys/contrib/ipfilter/netinet sys/netinet sys/netipsec sys/netpfil/pf
Message-ID:  <20150403112730.GP64665@FreeBSD.org>
In-Reply-To: <551E5C38.7070203@selasky.org>
References:  <551D8C6C.9060504@selasky.org> <alpine.BSF.2.11.1504021939390.64391@fledge.watson.org> <551DA5EA.1080908@selasky.org> <551DAC9E.9010303@selasky.org> <358EC58D-1F92-411E-ADEB-8072020E9EB3@FreeBSD.org> <551DEF26.4000403@selasky.org> <4B7DAA59-389F-41AE-99D8-034A7AA61C99@FreeBSD.org> <551E520E.1040708@selasky.org> <6DF5FB51-8135-4144-BD3A-6E4127A23AA7@FreeBSD.org> <551E5C38.7070203@selasky.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, Apr 03, 2015 at 11:24:08AM +0200, Hans Petter Selasky wrote:
H> What's described there is entirely about Peer2Peer communication. What 
H> I'm describing is broadcast for the whole system or firewall. Don't you 
H> understand that the IP ID counter is _linearly_ adding up and feeding 
H> back the sum to the source. It is like a radio channel for the whole 
H> firewall. Do you know how analog modems work? I have other things to do 
H> this easter and I don't want to spend more time with this either. I 
H> think the people responsible in the IP-stack area should make a fix. The 
H> IP ID must be randomized much more than it is today.

Please put

net.inet.ip.random_id=1

into your /etc/sysctl.conf, don't worry and be happy.

-- 
Totus tuus, Glebius.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20150403112730.GP64665>