From owner-freebsd-questions@FreeBSD.ORG Wed Oct 25 14:59:11 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2B9E616A415 for ; Wed, 25 Oct 2006 14:59:11 +0000 (UTC) (envelope-from lavalamp@spiritual-machines.org) Received: from mail.digitalfreaks.org (arbitor.digitalfreaks.org [216.151.95.158]) by mx1.FreeBSD.org (Postfix) with ESMTP id 7E32843D4C for ; Wed, 25 Oct 2006 14:59:10 +0000 (GMT) (envelope-from lavalamp@spiritual-machines.org) Received: by mail.digitalfreaks.org (Postfix, from userid 1022) id 31E6117E72; Wed, 25 Oct 2006 10:59:02 -0400 (EDT) Received: from localhost (localhost [127.0.0.1]) by mail.digitalfreaks.org (Postfix) with ESMTP id 2579817E71; Wed, 25 Oct 2006 10:59:02 -0400 (EDT) Date: Wed, 25 Oct 2006 10:59:01 -0400 (EDT) From: "Brian A. Seklecki" X-X-Sender: lavalamp@arbitor.digitalfreaks.org To: Alex Zbyslaw In-Reply-To: <453F62E1.5090506@dial.pipex.com> Message-ID: <20061025105710.N63561@arbitor.digitalfreaks.org> References: <453F62E1.5090506@dial.pipex.com> MIME-Version: 1.0 Content-Type: MULTIPART/MIXED; BOUNDARY="0-1784420763-1161788341=:63561" Cc: =?UTF-8?B?0KDQuNGF0LDQtCDQk9Cw0LTQttC40LXQsg==?= , freebsd-questions@freebsd.org Subject: Re: tcpwrappers & SSH X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 25 Oct 2006 14:59:11 -0000 This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. --0-1784420763-1161788341=:63561 Content-Type: TEXT/PLAIN; charset=iso-8859-1; format=flowed Content-Transfer-Encoding: 8BIT On Wed, 25 Oct 2006, Alex Zbyslaw wrote: > Рихад Гаджиев wrote: > >> A comment in /etc/hosts.allow states that: >> Wrapping sshd(8) is not normally a good idea With tcpwrappers, you still have to open a socket and burn cycles/ram/resources on the 3-way, followed by a quick RST. With pf(4), you can maintain a hash list on a L4 block rule and it's much more efficient. No RST needed. ~BAS --0-1784420763-1161788341=:63561--