Problem accessing https://my.procurve.com/profile/index.aspx
(ACK is over the upper bound)
Jozsef Kadlecsik
kadlec at blackhole.kfki.hu
Mon Jul 2 16:58:33 CEST 2007
On Mon, 2 Jul 2007, Patrick McHardy wrote:
>>> I'm a bit sceptical about NAT core caring about TCP conntrack
>>> specific sysctls, I'd prefer an unconditional drop.
>>
>> NAT works on top of conntrack so peeking the flags were not completely
>> perverse ;-). If NAT drops INVALID packets undconditionally, that'd
>> disable the sysctl flag completely and we had to say "this sysctl
>> setting cannot be used if the NAT module is loaded in".
>
> Would it really? The sysctls flag makes *more* packets be regarded
> as valid, so I'm not I'm following ..
You are right, sigh, I wrote rubbish.
Best regards,
Jozsef
-
E-mail : kadlec at blackhole.kfki.hu, kadlec at sunserv.kfki.hu
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
H-1525 Budapest 114, POB. 49, Hungary
More information about the netfilter-devel
mailing list