Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Filtering TCP establish
From: "Alastair Young" <alastair @ cadence . com>
Date: Fri, 31 Mar 1995 13:22:00 -0800
To: "Firewalls List" <firewalls @ GreatCircle . COM>
In-reply-to: "Peter Harrison" <harrison @ wellfleet . com . au> "Re: Filtering TCP establish" (Mar 25, 12:21am)
References: <199503241421 . AAA10786 @ nico . aarnet . edu . au>

> In the same vein, how would go about blocking all loose-source routed
> IP traffic on a particular interface?

I modified the ip_input.c that came with my Smallworks NetGate to drop all
source route packets and return a "source route unreachable" ICMP response.

The joy of a source license :-)

Al

-- 
----------------------------------------------------------------------------
Alastair Young                                     _  This vehicle incapable
Cadence Design Systems, Information Services     )/___     _  
555 River Oaks Parkway, 4B1                    __/(___)_*##/c of evading low 
San Jose CA 95134         Fax: (408)894-3487  / /\\|| \ /  \ 
alastair @
 cadence .
 com           (408)428-5278  \__/ ----'\__/  speed pursuit!
----------------------------------------------------------------------------
These statements and opinions are mine, not those of Cadence Design Systems




References:
Indexed By Date Previous: Satan
From: NEWTON Cesar <NCESAR @ prolan . com . br>
Next: Re: Microsoft SMTP Gateway
From: "Mark Norris" <mark @ uunet . uu . net>
Indexed By Thread Previous: Re: Filtering TCP establish
From: "Peter Harrison" <harrison @ wellfleet . com . au>
Next: Re: Filtering TCP establish
From: Geoffrey Sisson <geoff @ pipeline . com>

Google
 
Search Internet Search www.greatcircle.com