Subject: TCP SYN caching?
To: None <netbsd-help@NetBSD.ORG, tech-net@NetBSD.ORG>
From: Bob Sutterfield <Bob@XC.Org>
List: tech-net
Date: 10/07/1996 12:55:34
Does NetBSD 1.2 provide a FIFO cache for connections in the TCP
SYN_RECEIVED state, to guard against damage from SYN floods?  If not,
has anyone developed such a patch for NetBSD-Current that I could
apply to 1.1 and/or 1.2?  

(See ftp://info.cert.org/pub/cert_advisories/CA-96.21.tcp_syn_flooding
and ftp://ftp.bsdi.com/bsdi/patches/patches-2.1/K210-022 if you're not
already familiar with the issue.)

I see the recent discussion in the tech-net@netbsd.org archives, but
I'm not confident that a usable patch resulted!
--
Bob Sutterfield                         +1 909 794 1151
Mission Aviation Fellowship / MAFlink Technical Manager
mailto:Bob@XC.Org                 http://www.XC.Org/bob
             Pray Globally - Serve Locally