diff options
author | erwin <erwin@FreeBSD.org> | 2013-04-17 15:57:54 +0800 |
---|---|---|
committer | erwin <erwin@FreeBSD.org> | 2013-04-17 15:57:54 +0800 |
commit | d99283f9cfad75d2add0f6e9d334a205ed87ca79 (patch) | |
tree | 115667e2e8529746ad80d1d3db2c4466f8c29aae /www | |
parent | 0d9be530be19202276eeaa11571c1b18f2f0ec91 (diff) | |
download | freebsd-ports-gnome-d99283f9cfad75d2add0f6e9d334a205ed87ca79.tar.gz freebsd-ports-gnome-d99283f9cfad75d2add0f6e9d334a205ed87ca79.tar.zst freebsd-ports-gnome-d99283f9cfad75d2add0f6e9d334a205ed87ca79.zip |
Update RPZ+RRL patchset to the latest version.
The change makes "slip 1;" send only truncated (TC=1) responses.
Without the change, "slip 1;" is the same as the default of "slip 2;".
That default, which alternates truncated with dropped responses
when the rate limit is exceeded, is better for authoritative DNS
servers, because it further reduces the amplification of an attack
from about 1X to about 0.5X.
DNS RRL is not recommended for recursive servers.
Feature safe: yes
Diffstat (limited to 'www')
0 files changed, 0 insertions, 0 deletions