Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Scan of TCP 552-554

From: Rodrigo Barbosa <rodrigob(at)suespammers.org>
Date: Wed Jul 30 2003 - 16:59:07 EDT

On Wed, Jul 30, 2003 at 09:58:42AM -0400, Chris Shepherd wrote:
> You specifically say you have to trust your firewall, and then try and conceal

Lemme do same diet-quoting here.

You are right, of course. The thing I'm attempting is to make them hit my traps faster, so I can react faster. And, as I said, I don't think we should use the same method everywhere. Sametime I use DROP, sometimes I use tcp-reset and sometimes, icmp-replies.

As far as I got from this discussion, every method is about as good as the other. All have advantages and problems. The real question is how to balance them all to have the most benefits of each one of them. Care to comment on this one ?

[]s

-- 
Rodrigo Barbosa 
"Be excellent to each other ..." - Bill & Ted (Wyld Stallyns)

  • application/pgp-signature attachment: stored
Received on Thu Jul 31 10:45:44 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:14 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library