Subject: Re: Rate limiting ICMP responses?
To: John Klos , <tech-net@netbsd.org>
From: Matt Thomas <matt@3am-software.com>
List: tech-net
Date: 01/13/2002 17:29:11
At 08:21 PM 1/13/2002 -0500, John Klos wrote:
>Hi,
>
> > It's already in there.  From sysctl(2):
> >
> >       net.inet.icmp.errppslimit                    integer       yes
>
>That, apparently, limits the rate of some error or other. For example:
>reva: {31} sysctl net.inet.icmp.errppslimit
>net.inet.icmp.errppslimit = 10
>
>Then, from another host:
>xira: {1} ping -f reva
>PING reva.sixgirls.org (216.27.131.50): 56 data bytes
>^C
>----reva.sixgirls.org PING Statistics----
>779 packets transmitted, 779 packets received, 0.0% packet loss
>round-trip min/avg/max/stddev = 0.005/2.463/24.300/3.130 ms
>   368.7 packets/sec sent,  368.5 packets/sec received
>
>Obviously, reva is not limiting ICMP responses to 10 a second... So what
>DOES net.inet.icmp.errppslimit do? Searching NetBSD gives no clues.

echo replies are not ICMP errors.  :)  unreachable messages are (among
others).


-- 
Matt Thomas               Internet:   matt@3am-software.com
3am Software Foundry      WWW URL:    http://www.3am-software.com/bio/matt/
Cupertino, CA             Disclaimer: I avow all knowledge of this message