On Sep 6, 2011, at 19:29 , Tom Eastep wrote: > Shorewall can turns RP filtering and logging on or off; beyond that, > Shorewall has no control over how it works. When rp_filter is enabled on > an interface, an incoming packet is considered to be a martian if the > SOURCE IP address in the packet is not routed out of that interface. The > IP stack reverses the SOURCE and DESTINATION IP addresses and looks up > the appropriate route; if the route is out of a different interface, the > packet is a martian.
Thanks for your clarification. However, shouldn't the kernel check if the corresponding package is a DHCP Request and in this case skip the rp_filter as the source ip address will most likely be invalid? Or is there some special motivation for having rp_filter enabled for those packages as well? /Florian ------------------------------------------------------------------------------ Special Offer -- Download ArcSight Logger for FREE! Finally, a world-class log management solution at an even better price-free! And you'll get a free "Love Thy Logs" t-shirt when you download Logger. Secure your free ArcSight Logger TODAY! http://p.sf.net/sfu/arcsisghtdev2dev _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
