From owner-freebsd-security Thu May 31 12:14:48 2001 Delivered-To: freebsd-security@freebsd.org Received: from mail.wlcg.com (mail.wlcg.com [207.226.17.4]) by hub.freebsd.org (Postfix) with ESMTP id 108F937B43F for ; Thu, 31 May 2001 12:14:44 -0700 (PDT) (envelope-from rsimmons@wlcg.com) Received: from localhost (rsimmons@localhost) by mail.wlcg.com (8.11.3/8.11.3) with ESMTP id f4VJFUP05950; Thu, 31 May 2001 15:15:30 -0400 (EDT) (envelope-from rsimmons@wlcg.com) Date: Thu, 31 May 2001 15:15:26 -0400 (EDT) From: Rob Simmons To: Mike Silbersack Cc: freebsd-security@FreeBSD.ORG Subject: Re: Limiting TCP RST Response Packets In-Reply-To: <20010531135800.F73746-100000@achilles.silby.com> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org -----BEGIN PGP SIGNED MESSAGE----- Hash: RIPEMD160 Maybe that should be mentioned in LINT? Robert Simmons Systems Administrator http://www.wlcg.com/ On Thu, 31 May 2001, Mike Silbersack wrote: > > On Thu, 31 May 2001, Rob Simmons wrote: > > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: RIPEMD160 > > > > You will need to add the following line to your kernel config file, and > > recompile the kernel: > > > > options TCP_RESTRICT_RST > > > > You should also read the comments about this option in the LINT file. > > No. Bad. This is a paranoid response that will reduce the general > friendlyness of your box, and doesn't help much (if it all) more than > simply letting the built-in ratelimiting function. > > However, if you wish to reduce the rst packets per second, tune the > net.inet.icmp.icmplim sysctl. Don't reduce the count to zero, that means > unlimited. I find 20 to be a nice limit, personally. > > Mike "Silby" Silbersack > > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.5 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE7FphSv8Bofna59hYRAyTvAJ979VdkOCleyOBmXGN1avmhm+B3igCfZsXb GgT+DR70aWE6BPs5XufqAcM= =u7r3 -----END PGP SIGNATURE----- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message