看板FB_security
标 题Re: FreeBSD DDoS protection
发信站NCTU CS FreeBSD Server (Sun Feb 10 22:48:08 2013)
转信站ptt!csnews.cs.nctu!news.cs.nctu!.cs.nctucs.nctu!!freebsdfreebsd.org!ow
On 2013-02-10 03:57,
[email protected] wrote:
> Deny all ICMP (drop I mean) and UDP except where specifically required.
Please do not drop all ICMP unless you understand what you are doing. By
doing that you are creating a path MTU discovery blackhole.
See for example the following sites for more information:
http://www.phildev.net/mss/
https://supportforums.cisco.com/docs/DOC-5839
http://www.cymru.com/Documents/icmp-messages.html
http://packetlife.net/blog/2008/oct/09/disabling-unreachables-breaks-pmtud/
--
Janne Snabb / EPIPE Communications
[email protected] -
http://epipe.com/
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"