Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 5 Oct 2014 08:58:03 -0700
From:      Brandon Vincent <Brandon.Vincent@asu.edu>
To:        el kalin <kalin@el.net>
Cc:        freebsd-net <freebsd-net@freebsd.org>, freebsd-users@freebsd.org, freebsd-security@freebsd.org
Subject:   Re: remote host accepts loose source routed IP packets
Message-ID:  <CAJm423-mFg%2BzU_RB%2Bkp8wmp-V31onJJV0K4FUOLcv%2BczAOCKXA@mail.gmail.com>
In-Reply-To: <CAMJXockiQ%2B0gFbxSY43OyMbNqTjdzR1i16w%2Byiqmm=cQ8HR=pQ@mail.gmail.com>
References:  <CAMJXoc=s=Ud52NJ0dbK-6qKEcszbni4bi1MA8mgRtQSo=2Uuyw@mail.gmail.com> <CAMJXoc=5gs17ZgQ7LYALwKFRPN5hQ38OOuBtDk=EjZzi82EFMA@mail.gmail.com> <CAMJXockiQ%2B0gFbxSY43OyMbNqTjdzR1i16w%2Byiqmm=cQ8HR=pQ@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, Oct 5, 2014 at 8:33 AM, el kalin <kalin@el.net> wrote:
> should is submit this as a bug?

Can you first try adding "set block-policy return" to pf.conf? OpenVAS
might be assuming that a lack of response from your system to source
routed packets is an acknowledgement that it is accepting them.

Brandon Vincent



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAJm423-mFg%2BzU_RB%2Bkp8wmp-V31onJJV0K4FUOLcv%2BczAOCKXA>