mirror of
git://git.code.sf.net/p/xtables-addons/xtables-addons
synced 2026-05-28 05:19:43 +02:00
2b2b6246f0
This avoids DDoS on the first-in-sequence TCP knockport, which would otherwise fill up the peer table permanently - especially if the user does not specify --autoclose - and would thus cause permanent pknock DoS. Signed-off-by: Jan Rafaj <jr+netfilter-devel@cedric.unob.cz>