Firewall Wizards mailing list archives

Re: Wayyy too many spoofed packets


From: "Chris de Vidal" <chris () devidal tv>
Date: Fri, 21 Nov 2003 15:40:02 -0500 (EST)

Paul Robertson said:
It's probably just weird broadcast handling, since once your workstation
puts the packets out on the wire, and the destination is broadcast, it's
obligated to accept them off the wire so that an application can handle
them.

Ahh, now that makes sense.  The packet is being broadcast and the sending
interface is also the recieving interface and I get a match.

I'll see if I can add broadcast ignoring to that spoof protection.

Thanks!
/dev/idal
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: