Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 1 Aug 2003 16:44:13 +0200
From:      =?iso-8859-1?Q?Sten_Daniel_S=F8rsdal?= <sten.daniel.sorsdal@wan.no>
To:        <freebsd-ipfw@freebsd.org>
Subject:   Suggestion regarding a new option for IPFW2
Message-ID:  <0AF1BBDF1218F14E9B4CCE414744E70F07DEFE@exchange.wanglobal.net>

index | next in thread | raw e-mail


I have a humble suggestion to an IPFW2 option.

The option to send icmp error messages/tcp resets with src being
the original destination of the offending packet. 

I realize after looking at the src's that this might require a 
separate icmp_error() - please correct me if i'm wrong!

The intent is to "disguise" the source of the error message for
forwarding firewalls protecting servers.
Im thinking of a function like the one that is found in ipfilter.

Is this an option the community would appreciate?
Any thoughts and suggestions appreciated.

-- Sten


help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?0AF1BBDF1218F14E9B4CCE414744E70F07DEFE>