Matthew Seaman wrote:
[ ... ]
Now, that sounds quite reasonable, but it's really quite a minefield.
Consider that the TCP stream could be fragmented --- unlikely in
normal usage, but something a potential attacker might try --- or that
an attacker might be able to persuade your firewall to open up access
to ports or addresses it really shouldn't by sending a cunningly
modified FTP control exchange.
While I agree with this and the points you've made, let me suggest that the problem the original poster had is better solved by prioritizing traffic, rather than by setting fixed bandwidth limits in place. Or perhaps "in addition to fixed BW limits".

-Chuck



To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-questions" in the body of the message


Reply via email to