From owner-freebsd-hackers Tue Aug 22 15:27:10 1995 Return-Path: hackers-owner Received: (from majordom@localhost) by freefall.FreeBSD.org (8.6.11/8.6.6) id PAA20579 for hackers-outgoing; Tue, 22 Aug 1995 15:27:10 -0700 Received: from rover.village.org (rover.village.org [198.137.146.49]) by freefall.FreeBSD.org (8.6.11/8.6.6) with ESMTP id PAA20564 for ; Tue, 22 Aug 1995 15:27:00 -0700 Received: from localhost (localhost [127.0.0.1]) by rover.village.org (8.6.11/8.6.6) with SMTP id QAA11084; Tue, 22 Aug 1995 16:26:01 -0600 Message-Id: <199508222226.QAA11084@rover.village.org> To: guido@gvr.win.tue.nl (Guido van Rooij) Subject: Re: IPFW and SCREEND Cc: peter@haywire.dialix.com, freebsd-hackers@FreeBSD.ORG In-reply-to: Your message of Tue, 22 Aug 1995 21:03:49 +0200 Date: Tue, 22 Aug 1995 16:26:00 -0600 From: Warner Losh Sender: hackers-owner@FreeBSD.ORG Precedence: bulk : Just throw away *every* fragment that has as its start byte a byte in : the TCP/IP header. (so smaller then 40) That's the fix, but it isn't implemented yet in most Firewalls. Warner