summaryrefslogtreecommitdiffstats
path: root/sys/i386/conf
diff options
context:
space:
mode:
authordes <des@FreeBSD.org>2001-03-19 22:03:11 +0000
committerdes <des@FreeBSD.org>2001-03-19 22:03:11 +0000
commitd0f798c1511603114cebeb179c36e5b22f827f1b (patch)
treef1aee84c165162c8b0a65be0715f9ddf03d6f837 /sys/i386/conf
parent8b5320d4a50d269676d4e8c75120d565a3fc2dcc (diff)
downloadFreeBSD-src-d0f798c1511603114cebeb179c36e5b22f827f1b.zip
FreeBSD-src-d0f798c1511603114cebeb179c36e5b22f827f1b.tar.gz
Axe TCP_RESTRICT_RST. It was never a particularly good idea except for a few
very specific scenarios, and now that we have had net.inet.tcp.blackhole for quite some time there is really no reason to use it any more. (first of three commits)
Diffstat (limited to 'sys/i386/conf')
-rw-r--r--sys/i386/conf/NOTES8
1 files changed, 0 insertions, 8 deletions
diff --git a/sys/i386/conf/NOTES b/sys/i386/conf/NOTES
index 52f32ed..6dd2f65 100644
--- a/sys/i386/conf/NOTES
+++ b/sys/i386/conf/NOTES
@@ -590,19 +590,11 @@ options TCPDEBUG
options ACCEPT_FILTER_DATA
options ACCEPT_FILTER_HTTP
-# The following options add sysctl variables for controlling how certain
-# TCP packets are handled.
-#
# TCP_DROP_SYNFIN adds support for ignoring TCP packets with SYN+FIN. This
# prevents nmap et al. from identifying the TCP/IP stack, but breaks support
# for RFC1644 extensions and is not recommended for web servers.
#
-# TCP_RESTRICT_RST adds support for blocking the emission of TCP RST packets.
-# This is useful on systems which are exposed to SYN floods (e.g. IRC servers)
-# or any system which one does not want to be easily portscannable.
-#
options TCP_DROP_SYNFIN #drop TCP packets with SYN+FIN
-options TCP_RESTRICT_RST #restrict emission of TCP RST
# DUMMYNET enables the "dummynet" bandwidth limiter. You need
# IPFIREWALL as well. See the dummynet(4) manpage for more info.
OpenPOWER on IntegriCloud