>> > else if((ntohs(ip->tot_len)<8+(ip->ihl<<2))&&(ip->protocol==IPPROTO_TCP \
>> > || ip->protocol==IPPROTO_UDP))
>> > return FW_BLOCK;
>> > [...]
>> > methinks that blocking those "ugly" packets without any notification
>> > is a crime ;-) What about a simple patch ? (attached below)
>> Now allow me to send you millions of them filling your disk, driving your
>> load through the roof and generally becoming a denial of service issue.
>Which is what net_ratelimit() is for.
>[ This is done in my Generic IP chains patch -- gratuitous plug ].
Are there any chances to have your patch in official kernel
release or maybe ipfwadm lobby is to stroong ;-)
Kris
-- Krzysztof G. Baranowski - President of the Harmless Manyacs' Club "Smith & Wesson - The original point and click interface..." http://www.knm.org.pl/ <prezes@manjak.knm.org.pl>