On Sep 6, 2011, at 19:29 , Tom Eastep wrote:

> Shorewall can turns RP filtering and logging on or off; beyond that,
> Shorewall has no control over how it works. When rp_filter is enabled on
> an interface, an incoming packet is considered to be a martian if the
> SOURCE IP address in the packet is not routed out of that interface. The
> IP stack reverses the SOURCE and DESTINATION IP addresses and looks up
> the appropriate route; if the route is out of a different interface, the
> packet is a martian.

Thanks for your clarification.
However, shouldn't the kernel check if the corresponding package is a
DHCP Request and in this case skip the rp_filter as the source ip
address will most likely be invalid? Or is there some special
motivation for having rp_filter enabled for those packages as well?

/Florian

------------------------------------------------------------------------------
Special Offer -- Download ArcSight Logger for FREE!
Finally, a world-class log management solution at an even better 
price-free! And you'll get a free "Love Thy Logs" t-shirt when you
download Logger. Secure your free ArcSight Logger TODAY!
http://p.sf.net/sfu/arcsisghtdev2dev
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to