home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.protocols.tcp-ip
- Path: sparky!uunet!wupost!sdd.hp.com!usc!sol.ctr.columbia.edu!The-Star.honeywell.com!umn.edu!cs.umn.edu!kksys.com!edgar!brainiac!lmt!cgc.lmt.com!chrisc
- From: chrisc@ramrod.lmt.mn.org (Chris Cox)
- Subject: Re: Stopping only incoming TCP connections (was: Firewall usage)
- Message-ID: <chrisc.21.712446813@ramrod.lmt.mn.org>
- Sender: usenet@lmt.mn.org
- Nntp-Posting-Host: cgc.lmt.com
- Organization: LaserMaster Technologies, Minneapolis, MN USA
- References: <BrsM1C.36v@cs.columbia.edu> <DRW.92Jul27143657@jordan.mit.edu> <17011@ulysses.att.com> <1992Jul28.202211.14029@shearson.com>
- Date: Wed, 29 Jul 1992 21:53:33 GMT
- Lines: 22
-
- In article <1992Jul28.202211.14029@shearson.com> pmetzger@snark.shearson.com (Perry E. Metzger) writes:
-
- >I was under the impression that if you filter all the SYN packets from
- >one direction that aren't SYN ACKs, bingo, you can't initiate any
- >incoming TCP connections. Nice and stateless. The only flaw is that
- >implementations that seperately ACK the initiating SYN and then send
- >their own SYN won't be able to connect, but they are rare. Connections
-
- That would eliminate your users from starting ftp data sessions (wouldn't
- it?).
-
- Chris
-
- Chris Cox W0/G4JEC chrisc@ramrod.lmt.mn.org
- LaserMaster Technologies Tel: (612) 944-6069
- 7156 Shady Oak Road Fax: (612) 944-5544
- Eden Prairie, MN 55344
-
- ----- For mail of a more social nature, please use -----
-
- chrisc@moron.vware.mn.org -or- chrisc@biggus.g4jec.tcman.ampr.org
-
-