From nobody Sun Aug 11 13:47:28 2024 X-Original-To: freebsd-net@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Whf9f3MDJz5SqR1 for ; Sun, 11 Aug 2024 13:48:06 +0000 (UTC) (envelope-from kudzu@tenebras.com) Received: from mail-pg1-x536.google.com (mail-pg1-x536.google.com [IPv6:2607:f8b0:4864:20::536]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Whf9f1j3hz55fF for ; Sun, 11 Aug 2024 13:48:06 +0000 (UTC) (envelope-from kudzu@tenebras.com) Authentication-Results: mx1.freebsd.org; none Received: by mail-pg1-x536.google.com with SMTP id 41be03b00d2f7-7a1c7857a49so1957377a12.1 for ; Sun, 11 Aug 2024 06:48:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tenebras-com.20230601.gappssmtp.com; s=20230601; t=1723384084; x=1723988884; darn=freebsd.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=pWawn6zRENyPh+D+Hh/hKMdwNzvD+LRp5lq0yAzgVYA=; b=elvSvBowCfJhupLY5irPigD44/vCDJ/1T3MUjAAa7f3VsVC5TcP/Rxol2c/V9XMNtC T+LVAfk92+uCH/I1MrDDeVRPgtZUrMaq6+soa+f8WTgh5x78qCpLLc5VmZ6ywUEU2K1r BXGzg4NV4aGoGHKn0QA8MdjPxHjQczoejqW1b7wa5QT2Gfo+ZIKYUQixoy9MXat71SxQ Jg9jPT3SugWAZqhX9gAwcoHdhjyjL8VR72YbYpEXZROV07x6Ev5vc7d9OcUxGorBuM5M gc1GbVOkQ5pugkmHYlEJhOtAothXvB38qjViQNdrHcrPd9eKLxrwWo8Ho/JJTHvmftaB 9qTg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1723384084; x=1723988884; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=pWawn6zRENyPh+D+Hh/hKMdwNzvD+LRp5lq0yAzgVYA=; b=afS5UIpNmuF/HpPcgc6uZ6WsmrIFczen4JbYTPoueTXVgUg1gx9Rn9W2V4Q8d8/ndd sTPcFcUVyH0WOcGo6t+veeiJoANx+yJuJ9WwRstvIY0mNBF2pNBGu9J2X5VMn2mBjYDK DX3VbFZRjtSo5G7DLcLNLjpUAB/7zxjA6qGJD+bZHUWiHPP5JJS75cVWNiEkjVHJvuFF D2C2U0znxnfwqrU/qF52kOfgYehCEYT2Jem8wULAzFd1SF9/uCT2ue962IBM2nOxM50m RoG02B1QSBNng+d18c6X9hlJ6a/gHp6zS3FLkWQT8fhUsE0hB4qKuzV3rW0o3UJZQV/V KDdw== X-Gm-Message-State: AOJu0YxyyzKjDB/MIufBboZ3lzdPDAgtBay1Ebqx7wW/IuCt8qiMB1Qb 8rGPjmDbheEXHmq7I490/5GlFZH6Ze4RHLlEAuk80Ka4LYjT5MgJ9sL+lrUj1kxo4TDosrDyEz3 BWnrmL6tE2QnyG9ClV9NOvTmZxMnvMJ0THOJ4UqHvTHWymmFd5YU= X-Google-Smtp-Source: AGHT+IFJ9KweYUuNi/jgf7gVbgNhzXI4ROk8OoUepaMfoJszovFGYMFaZjpc/AQ9OvLnXg4sbE+2FXtjArPz9L07cAI= X-Received: by 2002:a05:6a21:e85:b0:1c2:96f1:a2ce with SMTP id adf61e73a8af0-1c89fe780acmr6267510637.3.1723384084430; Sun, 11 Aug 2024 06:48:04 -0700 (PDT) List-Id: Networking and TCP/IP with FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-net List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-net@FreeBSD.org MIME-Version: 1.0 References: In-Reply-To: From: Michael Sierchio Date: Sun, 11 Aug 2024 09:47:28 -0400 Message-ID: Subject: Re: drop synfin To: void Cc: freebsd-net@freebsd.org Content-Type: multipart/alternative; boundary="0000000000002a2153061f68a0e2" X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US] X-Rspamd-Queue-Id: 4Whf9f1j3hz55fF --0000000000002a2153061f68a0e2 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable sysrc is for editing rc files, and that's not what you want to do. you may manually set the MIB with sysctl net.inet.tcp.drop_synfin=3D1 or yo= u can put this line in /etc/sysctl.conf net.inet.tcp.drop_synfin=3D1 On Sun, Aug 11, 2024 at 9:24=E2=80=AFAM void wrote: > (originally posted to hackers@ but on second thoughts this ML is > more relevant) > > Hi, > > Is it sufficient to > > EITHER > > 1. # sysctl net.inet.tcp.drop_synfin=3D1 > > OR > > 2. # sysrc tcp_drop_synfin=3DYES > > or > > 3. must one do both ? > > -- > > --0000000000002a2153061f68a0e2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
sysrc is for editing rc files, and that's not what you= want to do.

you may manually set the MIB with sysctl net.inet.tcp.drop_synfin=3D1 or you can put t= his line in /etc/sysctl.conf

net.inet.tcp.drop_synfin=3D1


--0000000000002a2153061f68a0e2--