Eric Hidle on 28 Apr 2005 14:01:35 -0000 |
For every SYN there is a timeout while waiting for an ACK... by DROPing instead of REJECTing, the initiating host sits around waiting for the ACK. REJECT will send an ICMP message indicating that an ACK is not forthcoming, so the thread that is initiating the connection will know to give up immediately... E ----- Original Message ----- From: "Jeff Abrahamson" <jeff@purple.com> To: <plug@lists.phillylinux.org> Sent: Thursday, April 28, 2005 9:53 AM Subject: Re: [PLUG] Increase in SSH break-in attempts? > ___________________________________________________________________________ > Philadelphia Linux Users Group -- http://www.phillylinux.org > Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce > General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug > ___________________________________________________________________________ Philadelphia Linux Users Group -- http://www.phillylinux.org Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug
|
|