Re: A question about SYN cookies...

2013-02-07 Thread George Neville-Neil
On Feb 4, 2013, at 04:09 , Andre Oppermann wrote: > On 04.02.2013 01:09, George Neville-Neil wrote: >> Howdy, >> >> I've been reviewing the SYN cache and SYN cookie code and I'm wondering why >> we do all the work >> of generating a SYN cache entry before sending a SYN cookie. If the point >

Re: A question about SYN cookies...

2013-02-04 Thread Andre Oppermann
On 04.02.2013 01:09, George Neville-Neil wrote: Howdy, I've been reviewing the SYN cache and SYN cookie code and I'm wondering why we do all the work of generating a SYN cache entry before sending a SYN cookie. If the point of SYN cookies is to defend against a SYN flood then, to my mind, the

A question about SYN cookies...

2013-02-03 Thread George Neville-Neil
Howdy, I've been reviewing the SYN cache and SYN cookie code and I'm wondering why we do all the work of generating a SYN cache entry before sending a SYN cookie. If the point of SYN cookies is to defend against a SYN flood then, to my mind, the SYN/ACK for the cookie case should be sent off b