Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 02 Oct 2000 15:47:40 -0400
From:      Forrest Aldrich <forrie@forrie.com>
To:        freebsd-ipfw@freebsd.org
Subject:   4.1.1 Kernel ipfw, brought to its knees
Message-ID:  <5.0.0.25.2.20001002154554.01bfe310@64.20.73.233>

next in thread | raw e-mail | index | archive | help
I was working with our security person here at work, with my ipfw 
config.  I ran into some problems, which I'm still trying to figure out.

So, he offered to at least scan the machine.   He did a basic nmap scan... 
brought the machine to its knees.  I had ICMP bandwidth limitation 
enabled.  All except the RST (which isn't recommended for web servers).

The machine is rendered unusable.   I've never seen this happen to a 
FreeBSD box.  Our 2.2.8 systems withstand this better than this.

?


Forrest



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ipfw" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?5.0.0.25.2.20001002154554.01bfe310>