DoS, ICMP, proxies, SYNDefender

Perry E. Metzger perry at piermont.com
Thu Oct 3 23:02:41 UTC 1996


Tim Bass writes:
> On the SYNDefender firewall..... if we are interested in
> firewalls, then the 'elegant firewall solution' is, IMO,
> to insure that our gateways send ICMP UNREACHABLE messages
> back to the host.  Then it is somewhat easy to do the
> kernel checks to free SYN_REVC 'zombies'

It would also make it easier to nuke vital network communications
paths. Thanks, but I'll pass.

Perry





More information about the NANOG mailing list