Re: [Patch] IPv4 TCP security impovement

=?iso-8859-1?Q?Lars_Marowsky-Br=E9e?= (lmb@pointer.teuto.de)
Mon, 11 Jan 1999 13:58:53 +0100


On 1999-01-10T10:54:12,
"Brandon S. Allbery KF8NH" <allbery@kf8nh.apk.net> said:

> You seem to be certain that you'll never get a recycled IP address. I
> suggest you learn how the real world works; granted that recycling IPs
> quickly "isn't nice", nevertheless it happens. And it happens often enough
> that you have to deal with it.

While this is not l-k material per se:

Recycling IP addresses quickly is often necessary. Imagine a medium provider
with lets say 240 dialin ports (using up an entire /24) and approx 2-4 calls
going up and down per second on average, more during peak hours.

If you do not recycle IP addresses within a few minutes maximum, you suddenly
need a /23 to double the amount of time before an IP gets recycled,
effectively wasting 256 addresses, just to solve problems which occur when
some fool doesn't close all his TCP/IP connections before logging off.

I agree that the Linux kernel should have some magical way to detect that the
client side IP of an IP connection suddenly belongs to another host, but this
is not as easy as it sounds ;-)

Sincerely,
Lars Marowsky-Brée

--
Lars Marowsky-Brée
Network Management

teuto.net Netzdienste GmbH - DPN Verbund-Partner

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/