![rmind](/assets/img/avatar_default.png)
- Add proper TCP state tracking as described in Guido van Rooij paper, plus handle TCP Window Scaling option. - Completely rework npf_cache_t, reduce granularity, simplify code. - Add npf_addr_t as an abstraction, amend session handling code, as well as NAT code et al, to use it. Now design is prepared for IPv6 support. - Handle IPv4 fragments i.e. perform packet reassembly. - Add support for IPv4 ID randomization and minimum TTL enforcement. - Add support for TCP MSS "clamping". - Random bits for IPv6. Various fixes and clean-up.
$NetBSD: README,v 1.1 2008/11/13 10:06:46 ad Exp $ Do not automatically install modules that would fundamentally alter system behaviour or create a security hole, as the system may automatically load modules.