Re: IPFW2 versrcreach update
From: Petri Helenius (pete_at_he.iki.fi)
Date: 07/21/04
- Previous message: James: "Re: IPFW2 versrcreach update"
- In reply to: James: "Re: IPFW2 versrcreach update"
- Next in thread: James: "Re: IPFW2 versrcreach update"
- Reply: James: "Re: IPFW2 versrcreach update"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Wed, 21 Jul 2004 20:54:09 +0300 To: James <james@towardex.com>
James wrote:
>
>uRPF should not emit an ICMP when it drops a -reject route. Even with
>ip unreachables, Cisco won't emit ICMP when uRPF is killing a packet. The source
>that triggered uRPF drop condition cannot be trusted as it may have spoofed the
>packet.
>
>
>
Where would the ICMP go anyway because you either donīt have a route to
where you would point the packet to or the route points to null.
Pete
_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
- Previous message: James: "Re: IPFW2 versrcreach update"
- In reply to: James: "Re: IPFW2 versrcreach update"
- Next in thread: James: "Re: IPFW2 versrcreach update"
- Reply: James: "Re: IPFW2 versrcreach update"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|