Re: FIN_WAIT_2
From: Mike Silbersack (silby_at_silby.com)
Date: 03/26/05
- Previous message: Ruslan Ermilov: "Re: -I.. in sbin/ifconfig/Makefile"
- In reply to: Robert Gogolok: "Re: FIN_WAIT_2"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Sat, 26 Mar 2005 04:20:47 -0600 (CST) To: Robert Gogolok <robertgogolok@web.de>
On Tue, 22 Mar 2005, Robert Gogolok wrote:
> http://lists.freebsd.org/mailman/htdig/freebsd-ipfw/2003-May/000204.html is
> the same problem or similar problem.
> Forgot to mention thge important fact I use ipfw, bad bad...
>
> With
> # sysctl net.inet.ip.fw.dyn_keepalive=0
> the FIN_WAIT_2 connections cleaned all up within a few minutes.
>
>
> Robert
You probably shouldn't use ipfw stateful rules to protect FreeBSD; I
don't think it provides any benefit (unless you're using some concurrent
connection limiting or something.)
OTOH, blocking inbound packets to ports which are supposed to be unused
and using stateful rules to allow outbound connections is certainly a good
idea.
Mike "Silby" Silbersack
_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
- Previous message: Ruslan Ermilov: "Re: -I.. in sbin/ifconfig/Makefile"
- In reply to: Robert Gogolok: "Re: FIN_WAIT_2"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|
|