From owner-freebsd-security Thu May 31 11:45:48 2001 Delivered-To: freebsd-security@freebsd.org Received: from mail.wlcg.com (mail.wlcg.com [207.226.17.4]) by hub.freebsd.org (Postfix) with ESMTP id F2E2537B424 for ; Thu, 31 May 2001 11:45:42 -0700 (PDT) (envelope-from rsimmons@wlcg.com) Received: from localhost (rsimmons@localhost) by mail.wlcg.com (8.11.3/8.11.3) with ESMTP id f4VIkDd04707; Thu, 31 May 2001 14:46:13 -0400 (EDT) (envelope-from rsimmons@wlcg.com) Date: Thu, 31 May 2001 14:46:09 -0400 (EDT) From: Rob Simmons To: Liran Dahan Cc: freebsd-security@FreeBSD.ORG Subject: Re: Limiting TCP RST Response Packets In-Reply-To: <000a01c0ea06$be934600$b88f39d5@a> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org -----BEGIN PGP SIGNED MESSAGE----- Hash: RIPEMD160 You will need to add the following line to your kernel config file, and recompile the kernel: options TCP_RESTRICT_RST You should also read the comments about this option in the LINT file. Then you will need to add this line to your rc.conf file: tcp_restrict_rst="YES" or you can use the sysctl knob: net.inet.tcp.restrict_rst Robert Simmons Systems Administrator http://www.wlcg.com/ On Thu, 31 May 2001, Liran Dahan wrote: > Im afarid of someone trying to flood me by Connecting to me 1000 times > and for every time like that it will send TCP Rst Reponse. Is there > any way to Limit TCP Rst Response packets? Is there a way to Limit > Unreach Messages (IPFW) that it wont flood me too ? > > -Liran Dahan- (lirandb@netvision.net.il) > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.5 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE7FpF1v8Bofna59hYRA/uBAJ43eCmPWdjrBK3DTt1DKCnSA5k0KwCdGMAa MgbhLld2PtM7xBxEEuXfcgc= =7UMY -----END PGP SIGNATURE----- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message