Hello! I'm trying to implement a way to add some protection against ICMP DF set but fragmentation required packets spoofing. This is a netfilter hook that should implement an HMAC based protection, but I'm not sure that my code is sane, and before to post it to bugtraq, and crash all the boxes of the users that will load the module, I want to learn if it's ok. Thanks in advance for your support. p.s. obviously comments about the protection design used will help as weel. -- Salvatore Sanfilippo | http://www.kyuzz.org/antirez | PGP: finger antirez@tella.alicom.com