Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 02 May 2014 11:50:16 +0200
From:      =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= <des@des.no>
To:        Mike Tancsa <mike@sentex.net>
Cc:        freebsd-security@freebsd.org
Subject:   Re: FreeBSD Security Advisory FreeBSD-SA-14:08.tcp
Message-ID:  <86y4ykik6f.fsf@nine.des.no>
In-Reply-To: <53610127.5000603@sentex.net> (Mike Tancsa's message of "Wed, 30 Apr 2014 09:56:55 -0400")
References:  <201404300435.s3U4ZAw1093717@freefall.freebsd.org> <53610127.5000603@sentex.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Mike Tancsa <mike@sentex.net> writes:
> Is [scrub in all] the only pf option that will work, or is scrub
> fragment reassemble sufficient ?

"fragment reassemble" is implicit, but if you leave out "in" it will
also scrub outgoing traffic, which is wasteful.

DES
--=20
Dag-Erling Sm=C3=B8rgrav - des@des.no



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?86y4ykik6f.fsf>