[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

CVS: cvs.openbsd.org: src



CVSROOT:	/cvs
Module name:	src
Changes by:	dhartmei_(_at_)_cvs_(_dot_)_openbsd_(_dot_)_org	2003/05/16 11:15:18

Modified files:
	sys/net        : pfvar.h pf.c 
	sbin/pfctl     : parse.y pf_print_state.c pfctl_parser.c 
	share/man/man5 : pf.conf.5 

Log message:
TCP SYN proxy. Instead of 'keep state' or 'modulate state', one can use
'synproxy state' for TCP connections. pf will complete the TCP handshake
with the active endpoint before passing any packets to the passive end-
point, preventing spoofed SYN floods from reaching the passive endpoint.

No additional memory requirements, no cookies needed, random initial
sequence numbers, uses the existing sequence number modulators to translate
packets after the handshakes.

ok frantzen@



Visit your host, monkey.org