Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 30 Apr 2014 09:56:55 -0400
From:      Mike Tancsa <mike@sentex.net>
To:        freebsd-security@freebsd.org
Subject:   Re: FreeBSD Security Advisory FreeBSD-SA-14:08.tcp
Message-ID:  <53610127.5000603@sentex.net>
In-Reply-To: <201404300435.s3U4ZAw1093717@freefall.freebsd.org>
References:  <201404300435.s3U4ZAw1093717@freefall.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On 4/30/2014 12:35 AM, FreeBSD Security Advisories wrote:
> IV.  Workaround
>
> It is possible to defend to these attacks by doing traffic normalization
> using a firewall.  This can be done by including the following /etc/pf.conf
> configuration:
>
> 	scrub in all

Hi,
	Is this the only pf option that will work, or is
scrub fragment reassemble
sufficient ?

	---Mike


-- 
-------------------
Mike Tancsa, tel +1 519 651 3400
Sentex Communications, mike@sentex.net
Providing Internet services since 1994 www.sentex.net
Cambridge, Ontario Canada   http://www.tancsa.com/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?53610127.5000603>