socket policy
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- >>>>> "itojun" == itojun <[email protected]> writes: itojun> one. i am particularly interested in socket-based policy, itojun> tcp handling, listening socket policy handling (do you itojun> respond to unencrypted SYN with unencrypted RST if the socket itojun> is set to "require IPsec"?) That's a hard one. I think that you should reply with ICMP port unreachable. That's my opinion. ] Out and about in Ottawa. hmmm... beer. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON |net architect[ ] [email protected] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian/notebook using, kernel hacking, security guy"); [ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) Comment: Finger me for keys - custom hacks make this fully PGP2 compat iQCVAwUBP0EE4IqHRg3pndX9AQETQQP9EntOLbf4325/0tkUU1jVCzyEjbSKQZdF z55P/zVkFBH9rXHkrDc3/r/gx0a/NPPzD4JZyOfYaETBCmxCbZMJBBw6pwct2YMi iE5cmfGd78FGbLYC7LmKJqYB9qMq0tXqJ4s6a/3N1S4p/+iK2Yfcw6ks1G3BrvkP EGin+AMTpiA= =oVBO -----END PGP SIGNATURE-----