Re: netfilter plugin: antispoof

Lars Marowsky-Bree (lmb@teuto.net)
Tue, 14 Sep 1999 08:21:32 +0200


On 1999-09-13T21:39:05,
Rik van Riel <riel@humbolt.geo.uu.nl> said:

> Basically, it terminates IP connections that it doesn't
> know of. This makes pretty sure that people trying to
> do IP spoofing (because they're along the path) get their
> connections terminated immediately because the victim
> machine hasn't done the negotiations itself.

How is this different from basic stateful packet filtering, which Netfilter
should already be able to do?

> I don't know how quickly a connection can be terminated
> or how effective this measure could be, but a FIN/FINACK
> combo shouldn't be too hard, now should it?

Just send a port / destination unreachable.

Sincerely,
Lars Marowsky-Brée

--
Lars Marowsky-Brée
Network Management

teuto.net Netzdienste GmbH

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/