Re: [RFC PATCH] network: return errors if we know tcp_connectfailed

From: David Miller
Date: Fri Nov 12 2010 - 16:17:58 EST


From: David Lamparter <equinox@xxxxxxxxxx>
Date: Fri, 12 Nov 2010 22:16:27 +0100

> As food for thought I'd like to pose the following rule:
> iptables -A OUTPUT -m statistic --mode nth --every 5 -j DROP
> which should, to my understanding, still allow the connect to complete,
> even if the first SYN got (silently!...) dropped.

Yes, I agree and this is pretty much the point I tried to make
earlier.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/