From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michel Banguerski Subject: Re: Syncookie firewall Date: Fri, 07 Jun 2002 11:47:22 +0200 Sender: netfilter-devel-admin@lists.samba.org Message-ID: <3D00812A.7000106@laposte.net> References: <20020606020322.05BF64258@lists.samba.org> <15615.36281.187120.257236@isis.cs3-inc.com> <200206061932.04510.hno@marasystems.com> <3D007B24.9010804@laposte.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Return-path: To: netfilter-devel@lists.samba.org Errors-To: netfilter-devel-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Unsubscribe: , List-Archive: List-Id: netfilter-devel.vger.kernel.org Michel Banguerski wrote: [....] > > BTW: I'm not 100% sure but it seems to me that at least inversion 4.1 > Checkpoint FW1 was rejecting by default packets with *ANY* TCP > option , and people were "happy" with that :-) > (of course vendors lasyness is ont a good reason for doing bad design) > Ooops ! It was *IP* options, not *TCP*. I'm sorry, plz don't falme ... Regards Michel