Gaspar, 2008/11/25 Gáspár Lajos <swifty@xxxxxxxxxxx>: > Hi! > > I use the following five combination to filter bogous packets: Why those in particular, and not the others? Your set also adds one mask/comp pair, RST,FIN RST,FIN It seems that just about every example uses a different combination of fragment rules. I'm simply wondering what the logic in choosing one over the other is. Is there maybe some documentation you can point to? --JC -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html