From mboxrd@z Thu Jan 1 00:00:00 1970 From: Patrick McHardy Subject: Re: patch: Port- and netscan detection for netfilter Date: Fri, 16 Mar 2007 17:57:59 +0100 Message-ID: <45FACC97.2050701@trash.net> References: <45FABA87.4090601@trash.net> <45FAC7B7.40806@tpi.com> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: 7bit Cc: netfilter-devel@lists.netfilter.org, "Gladewitz, Robert \(FH\)" To: Tim Gardner Return-path: In-Reply-To: <45FAC7B7.40806@tpi.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-devel-bounces@lists.netfilter.org Errors-To: netfilter-devel-bounces@lists.netfilter.org List-Id: netfilter-devel.vger.kernel.org Tim Gardner wrote: > Patrick, > > One benefit of being able to block a port scanner is that it reduces or > stops the amount of ARP traffic that is generated. Depending on your > internal network design, lots of ARP traffic can have a significant > impact on WAN links and so on. Good point.