Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 3 Apr 2003 23:53:27 +0200
From:      jeremie le-hen <>
Subject:   Implementing ranges in ipfw2
Message-ID:  <>

Next in thread | Raw E-Mail | Index | Archive | Help

I going to implement ranges for IPLEN using the same way as for transport
layer ports (struct _ipfw_insn_u16). But I'm wondering if this kind of test
should be only applied on first/only fragments, since a malicious application
could use small fragment in order to bypass firewall rules.

I'm waiting for your comments.
Jeremie aka TtZ

Want to link to this message? Use this URL: <>