HomeFreeBSD

Add to ipfw support for sending an SCTP packet containing an ABORT chunk.

Description

Add to ipfw support for sending an SCTP packet containing an ABORT chunk.
This is similar to the TCP case. where a TCP RST segment can be sent.

There is one limitation: When sending an ABORT in response to an incoming
packet, it should be tested if there is no ABORT chunk in the received
packet. Currently, it is only checked if the first chunk is an ABORT
chunk to avoid parsing the whole packet, which could result in a DOS attack.

Thanks to Timo Voelker for helping me to test this patch.
Reviewed by: bcr@ (man page part), ae@ (generic, non-SCTP part)
Differential Revision: https://reviews.freebsd.org/D13239

Details

Provenance
tuexenAuthored on
Differential Revision
D13239: Add support for ABORT action in ipfw
Parents
rS326232: Addd work around for LLVM bug 35023.
Branches
Unknown
Tags
Unknown