Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 22 Jan 2003 11:27:38 -0800 (PST)
From:      Mike Hoskins <mike@adept.org>
To:        freebsd-security@FreeBSD.ORG
Subject:   Re: Limiting icmp unreach response from 231 to 200 packets per second
Message-ID:  <20030122112600.G12348-100000@fubar.adept.org>
In-Reply-To: <014b01c2c182$b93b5da0$34a8a8c0@melim.com.br>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, 21 Jan 2003, Ronan Lucio wrote:
> > 1.  BIND crashes.
> > 2.  DNS requests keep coming in, at a rate of 231 per second.
> > 3.  FreeBSD limits the number of icmp unreach responses, and tells you.
> > 4.  You restart BIND, and messages go away.
> > I can't answer why step #1 occured, but I can assure you that #2 through
> > #4 are natural results of #1, and are nothing to worry about it.

See bind9-users for that.  (Recent discussion.)

> I think a good solution is install a DJB DNS Cache and leave it
> just to answer DNS queries.

If you can stand DJB's rhetoric.  Sure, he seems like a smart enough
guy...  If he wasn't such an a$$.  I guess that's a problem with a lot of
"smart" people though.

--
Mike Hoskins		This message is RFC 1855 compliant,
mike@adept.org		www.adept.org/pub/rfcs/rfc1855.html


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030122112600.G12348-100000>