Subject: Re: Interface devices and security
To: None <port-i386@netbsd.org>
From: Thilo Manske <Thilo.Manske@HEH.Uni-Oldenburg.DE>
List: port-i386
Date: 12/21/1998 23:53:07
In message <01BE2CED.1D1A0B70.stevep@mccue.com>
          Steve Paul <stevep@mccue.com> wrote:
> Is there some method or interface/kernal patch to make the=20
> server reject oversized packets/icmp data?  Or maybe some
> listener program that shuts off these ports on detection of
> possible flood?

Maybe the "IP Filter" software that comes with NetBSD 1.3 is all you
need.=20

Please see http://coombs.anu.edu.au/~avalon/ip-filter.html , ipf(5),
ipf(8), /usr/share/examples/ipf/* for more information about it.

Bye,
  Thilo.
--=20
Mir ist mein Signature entlaufen :-(. Wer es findet, sende es bitte an
Thilo.Manske@HEH.Uni-Oldenburg.DE zur=FCck. Danke!=20