Re: source limit

Just as a note (i don't want to do more OT but a clarify note is needed).
IPFW don't check ISN and/or windows size in it statuful engine and in IPFW2
are kept in meomory and checked only to send realtive 'keep alive' signal.
This is not due to broken code but only to a choice.
Maybe the choice could be discussed on but this is not the place.
>not need to predirect TCP ISNs for ipfw !
>ipfw doesn't store any TCP ISN in ipfw dynamic state!!
>and finally with TCP flags RST. It work in ipfw!!
>for ipfw2. it seems that it may work!  the sequence checking in ipfw2 still
>doesn't check completely like pf or ipfilter.
