RE: FreeBSD Security Advisory FreeBSD-SA-16:16.ntp

2016-04-29 Thread Matthew X. Economou
Roger Marquis writes: > > What are the reasons FreeBSD has not deprecated ntpd in favor of > openntpd? While I cannot speak for anyone other than myself, the two simply aren't equivalent. As a conscious design choice, OpenNTPD trades off accuracy for code simplicity. It lacks support for NTP au

RE: FreeBSD DDoS protection

2013-02-13 Thread Matthew X. Economou
khatfield@s... Writes: > > The less you do with the firewall (routing/blocking/inspecting) the > better. > > Drop drop drop ;) I think this is really bad advice. A firewall should return destination-unreachable/reset packets for administratively prohibited traffic types. Drops, null routes, et