From owner-freebsd-net@FreeBSD.ORG Sat Mar 1 20:27:48 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 713B6106567F for ; Sat, 1 Mar 2008 20:27:48 +0000 (UTC) (envelope-from silby@silby.com) Received: from relay03.pair.com (relay03.pair.com [209.68.5.17]) by mx1.freebsd.org (Postfix) with SMTP id F144A8FC14 for ; Sat, 1 Mar 2008 20:27:47 +0000 (UTC) (envelope-from silby@silby.com) Received: (qmail 42030 invoked from network); 1 Mar 2008 20:27:46 -0000 Received: from unknown (HELO localhost) (unknown) by unknown with SMTP; 1 Mar 2008 20:27:46 -0000 X-pair-Authenticated: 209.68.2.70 Date: Sat, 1 Mar 2008 14:27:45 -0600 (CST) From: Mike Silbersack To: Fernando Gont In-Reply-To: <200803011338.m21DcY9Z026418@venus.xmundo.net> Message-ID: <20080301142538.L29763@odysseus.silby.com> References: <200803011338.m21DcY9Z026418@venus.xmundo.net> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed Cc: Rui Paulo , freebsd-net@freebsd.org Subject: Re: Ephemeral port range (patch) X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 01 Mar 2008 20:27:48 -0000 On Sat, 1 Mar 2008, Fernando Gont wrote: > Folks, > > This patch changes the default ephemeral port range from 49152-65535 to > 1024-65535. This makes it harder for an attacker to guess the ephemeral ports > (as the port number space is larger). Also, it makes the chances of port > number collisions smaller. > (http://www.ietf.org/internet-drafts/draft-ietf-tsvwg-port-randomization-01.txt) There are a number of commonly used ports above 1000, such as nfs and x11. I think OpenBSD uses 10000-65535, maybe that's a safer choice to go with. -Mike