Re: [IPV4] LVS: Allow to send ICMP unreachable responses when real-servers are removed
From: David Miller <davem@davemloft.net>
Date: 2007-05-17 20:51:21
From: David Miller <davem@davemloft.net>
Date: 2007-05-17 20:51:21
From: Patrick McHardy <redacted> Date: Thu, 17 May 2007 18:40:28 +0200
In any case some better solution than the current one needs to be found, allowing users to send spoofed packets is far worse than using a non-desired source address for ICMP packets.
Agreed, but it only occurs if the nonlocal bind sysctl is enabled and almost nobody turns that thing on :-)