Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 1 Aug 2003 16:44:13 +0200
From:      =?iso-8859-1?Q?Sten_Daniel_S=F8rsdal?= <sten.daniel.sorsdal@wan.no>
To:        <freebsd-ipfw@freebsd.org>
Subject:   Suggestion regarding a new option for IPFW2
Message-ID:  <0AF1BBDF1218F14E9B4CCE414744E70F07DEFE@exchange.wanglobal.net>

next in thread | raw e-mail | index | archive | help

I have a humble suggestion to an IPFW2 option.

The option to send icmp error messages/tcp resets with src being
the original destination of the offending packet.=20

I realize after looking at the src's that this might require a=20
separate icmp_error() - please correct me if i'm wrong!

The intent is to "disguise" the source of the error message for
forwarding firewalls protecting servers.
Im thinking of a function like the one that is found in ipfilter.

Is this an option the community would appreciate?
Any thoughts and suggestions appreciated.

-- Sten



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?0AF1BBDF1218F14E9B4CCE414744E70F07DEFE>