Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 13 May 2004 01:23:44 -0700
From:      Luigi Rizzo <rizzo@icir.org>
To:        Eugene Grosbein <eugen@kuzbass.ru>
Cc:        net@freebsd.org
Subject:   Re: ipfw: reset tcp
Message-ID:  <20040513012344.A12373@xorpc.icir.org>
In-Reply-To: <40A3393F.1391943E@kuzbass.ru>; from eugen@kuzbass.ru on Thu, May 13, 2004 at 05:00:47PM %2B0800
References:  <40A3393F.1391943E@kuzbass.ru>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, May 13, 2004 at 05:00:47PM +0800, Eugene Grosbein wrote:
> Hi!
> 
> When a rule 'reset tcp' matches, a kernel generates new TCP packet.
> Will it have to go through ipfw list (from the beginning or not)?

ipfw2 uses an mbuf flag to bypass the firewall - I am not sure if i
only used it for the keepalives or also for TCP reset packets

cheers
luigi



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040513012344.A12373>