Your message dated: Thu, 31 Jul 97 17:34:01 +0200
>  * Drop source routes pakets
Drop packets that have a source route flag set. This stops simpliest
redirection attacks and should be always set to yes.
>  * always defragment
Reassemble packet from fragments first and only after that apply firewalling
rulesets. Unless you have a really good reason not to do this ( and I am yet
to hear one ), it should be set t yes.
Alex
-----------------------------------------------------------------------------
Alex "Mr. Worf" Yuriev         Nationwide ISP Bandwidth: 
[www.netaxs.net   ]
Net Access                     Outsourced News Reading:   [www.newsread.com ]
alex@{netaxs.com|yuriev.com}   Outsourced Shell Accounts: [shellaccounts.com]
   RIP is irrelevant. Spoofing is futile. Your routes will be aggregated.
-----------------------------------------------------------------------------