Re: D.O.S. attack protection enhancements commit (ICMP_BANDLIM)

[ Available lists | Index of freebsd-current | Month of Dec 1998 | Week of 1 Dec 1998 | Raw email | View thread | Wrap long lines | Reply | Tag ]
From
Mike Smith <mike@smith.net.au>
Date
1 Dec 1998 15:35:21
Subject
Re: D.O.S. attack protection enhancements commit (ICMP_BANDLIM)
Message-ID
199812012333.PAA00825@dingo.cdrom.com

In reply to

[ Hide this part ]
> :general scheme implemented perhaps inside the ipfw framework would be more
> :appropriate. I also generally like to avoid compile time options for things
> :like this, but I"m sympathetic for performance reducing enhancements.
> :
> :-DG
>
> I figure we would make it the default in 6 months to a year, but
> we should have it optioned initially so people can play with it
> and also because it defaults to enabled when optioned-in, which I
> think is important.

Just a consideration; if possible, make it run-time tunable with a
boolean sysctl variable. (ie. if the 'off' case is comparable to the
'optioned-out' case in terms of speed.)

--
\\ Sometimes you're ahead, \\ Mike Smith
\\ sometimes you're behind. \\ mike@smith.net.au
\\ The race is long, and in the \\ msmith@freebsd.org
\\ end it's only with yourself. \\ msmith@cdrom.com



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-current" in the body of the message


Elapsed time: 0.244 seconds