
Firewall Wizards mailing list archives
Inappropriate TCP Resets Considered Harmful
From: Sally Floyd <floyd () aciri org>
Date: Tue, 08 May 2001 20:34:54 -0700
I am new to this mailing list, but I wanted to point people here to a new internet-draft of mine on "Inappropriate TCP Resets Considered Harmful", at "http://www.ietf.org/internet-drafts/draft-floyd-tcp-reset-00.txt", which argues that firewalls should not send TCP Resets (RST) in response to TCP SYN packets that contain flags in the TCP Reserved field. (Of 24,000 or so web servers that we tested as part of the TBIT project, only 300 or so were behind firewalls that send TCP resets in this case, so clearly most of the world seems to be maintaining reasonably adequate security without sending TCP Resets in this case.) I just learned of this mailing list, so I thought that, as long as I was writing something directed in part at firewall behavior, I would send it to this list for feedback. Thanks, - Sally http://www.aciri.org/floyd/ _______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://www.nfr.com/mailman/listinfo/firewall-wizards
Current thread:
- Inappropriate TCP Resets Considered Harmful Sally Floyd (May 10)
- FW Sequence Number based statefulness Nimesh vakharia (May 11)
- Re: FW Sequence Number based statefulness Carson Gaspar (May 13)
- <Possible follow-ups>
- RE: Inappropriate TCP Resets Considered Harmful dave . goldsmith (May 11)
- RE: Inappropriate TCP Resets Considered Harmful Ben Nagy (May 11)
- RE: Inappropriate TCP Resets Considered Harmful Ofir Arkin (May 13)
- Re: Inappropriate TCP Resets Considered Harmful Darren Reed (May 13)
- Re: Inappropriate TCP Resets Considered Harmful Sally Floyd (May 13)
- Re: Inappropriate TCP Resets Considered Harmful Darren Reed (May 14)
- RE: Inappropriate TCP Resets Considered Harmful Ben Nagy (May 14)
- RE: Inappropriate TCP Resets Considered Harmful Ben Nagy (May 14)
(Thread continues...)
- FW Sequence Number based statefulness Nimesh vakharia (May 11)