Gentoo Archives: gentoo-security

From: Frank Gruellich <frank@××××××××××××.org>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] firewall suggestions?
Date: Thu, 08 Jan 2004 14:49:59
Message-Id: 20040108143757.GE4413@home.manuelm.org
In Reply to: Re: [gentoo-security] firewall suggestions? by "Thomas T. Veldhouse"
1 * Thomas T. Veldhouse <veldy@×××××.net> 8. Jan 04
2 > Oliver Schad wrote:
3 > > [DROP or REJECT]
4 > One reason ... it slows down various scans.
5
6 No, it doesn't. It would, if $scanner sends one SYN and wait for the
7 answer to it. In fact it sends you SYNs to all your ports at once and
8 collects answers (or not) in parallel. You extend the scan time for one
9 timeout (which is nothing (~3min?) against the time to send all
10 requests).
11
12 Don't do that,
13 regards, Frank.
14 --
15 Sigmentation fault
16
17 --
18 gentoo-security@g.o mailing list