mirror of
git://git.code.sf.net/p/xtables-addons/xtables-addons
synced 2025-12-09 09:33:53 +01:00
This avoids DDoS on the first-in-sequence TCP knockport, which would otherwise fill up the peer table permanently - especially if the user does not specify --autoclose - and would thus cause permanent pknock DoS. Signed-off-by: Jan Rafaj <jr+netfilter-devel@cedric.unob.cz>
9.8 KiB
9.8 KiB