Em Saturday 16 January 1999 10:06, Erlon Sousa Pinheiro escreveu:
> � s� que eu j� fiz isso e n�o resolveu... realmente tem esse
> par�metro... mas ele funciona aleat�riamente e no meu caso � estranho
> porque ap�s o d�cimo pacote ele perde os impares.

Ent�o por que n�o deixar como est�? Al�m de n�o interferir com a 
comunica��o entre as m�quinas, ainda protege sua rede contra ataques de 
nega��o de servi�o (DoS). 

Usamos o CL7.0 assim em diversas configura��es e o desempenho das 
m�quinas � elogiado pelos clientes.

O Linux oferece v�rios recursos de seguran�a para limitar tentativas de 
derrubar as m�quinas que foram implementadas  e a Conectiva, 
espertamente, resolveu us�-las.

Apenas para voc� ficar tranq�ilo de que o CL7.0 funciona normal, eu fiz 
uns testes de ping para provar para voc� que funciona perfeito. Veja

$ ping 10.0.0.10
PING 10.0.0.10 (10.0.0.10): 56 data bytes
64 bytes from 10.0.0.10: icmp_seq=0 ttl=255 time=1.0 ms
64 bytes from 10.0.0.10: icmp_seq=1 ttl=255 time=0.5 ms
64 bytes from 10.0.0.10: icmp_seq=2 ttl=255 time=0.5 ms
64 bytes from 10.0.0.10: icmp_seq=3 ttl=255 time=0.5 ms
64 bytes from 10.0.0.10: icmp_seq=4 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=5 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=6 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=7 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=8 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=9 ttl=255 time=0.5 ms
64 bytes from 10.0.0.10: icmp_seq=10 ttl=255 time=0.5 ms
64 bytes from 10.0.0.10: icmp_seq=12 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=14 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=16 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=18 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=20 ttl=255 time=0.5 ms

--- 10.0.0.10 ping statistics ---
21 packets transmitted, 16 packets received, 23% packet loss
round-trip min/avg/max = 0.5/0.5/1.0 ms

Como voc� reportou, a partir do 10� pacote, ele perde os pacotes 
�mpares. 

S� que consultando a documenta��o do ping, eu posso diminuir a taxa de 
pings de 1 para 2 segundos.

$ ping -i 2 10.0.0.10
PING 10.0.0.10 (10.0.0.10): 56 data bytes
64 bytes from 10.0.0.10: icmp_seq=0 ttl=255 time=0.7 ms
64 bytes from 10.0.0.10: icmp_seq=1 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=2 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=3 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=4 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=5 ttl=255 time=0.5 ms
64 bytes from 10.0.0.10: icmp_seq=6 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=7 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=8 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=9 ttl=255 time=0.9 ms
64 bytes from 10.0.0.10: icmp_seq=10 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=11 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=12 ttl=255 time=0.9 ms
64 bytes from 10.0.0.10: icmp_seq=13 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=14 ttl=255 time=0.9 ms
64 bytes from 10.0.0.10: icmp_seq=15 ttl=255 time=0.8 ms
64 bytes from 10.0.0.10: icmp_seq=16 ttl=255 time=0.6 ms
64 bytes from 10.0.0.10: icmp_seq=17 ttl=255 time=0.9 ms
64 bytes from 10.0.0.10: icmp_seq=18 ttl=255 time=0.7 ms
64 bytes from 10.0.0.10: icmp_seq=19 ttl=255 time=0.5 ms
64 bytes from 10.0.0.10: icmp_seq=20 ttl=255 time=0.8 ms

--- 10.0.0.10 ping statistics ---
21 packets transmitted, 21 packets received, 0% packet loss
round-trip min/avg/max = 0.5/0.6/0.9 ms

Viu? N�o perdeu nenhum pacote.

Assim, fica imposs�vel fazer um ataque usando fping (Fast Ping) ou ping 
-f.

Se voc� fizer o teste de ping na pr�pria m�quina, usando o loopback 
127.0.0.1, vai ver que a m�quina n�o perde nenhum pacote, mesmo com 
taxa de 1 segundo.

O que significa que a m�quina foi configurada para se proteger contra 
tentativas EXTERNAS maldosas de conex�o.

$ ping 127.0.0.1
PING 127.0.0.1 (127.0.0.1): 56 data bytes
64 bytes from 127.0.0.1: icmp_seq=0 ttl=255 time=2.6 ms
64 bytes from 127.0.0.1: icmp_seq=1 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=2 ttl=255 time=0.2 ms
64 bytes from 127.0.0.1: icmp_seq=4 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=5 ttl=255 time=0.2 ms
64 bytes from 127.0.0.1: icmp_seq=6 ttl=255 time=0.2 ms
64 bytes from 127.0.0.1: icmp_seq=7 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=8 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=9 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=10 ttl=255 time=0.2 ms
64 bytes from 127.0.0.1: icmp_seq=11 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=12 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=13 ttl=255 time=0.2 ms
64 bytes from 127.0.0.1: icmp_seq=14 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=15 ttl=255 time=0.2 ms
64 bytes from 127.0.0.1: icmp_seq=16 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=17 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=18 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=19 ttl=255 time=0.1 ms
64 bytes from 127.0.0.1: icmp_seq=20 ttl=255 time=0.2 ms

--- 127.0.0.1 ping statistics ---
21 packets transmitted, 21 packets received, 0% packet loss
round-trip min/avg/max = 0.1/0.2/2.6 ms

[]s e Feliz Natal.

-- 
Edgard Lemos 
[EMAIL PROTECTED]
Usu�rio Linux n� 135479


Assinantes em 23/12/2001: 2311
Mensagens recebidas desde 07/01/1999: 147577
Historico e [des]cadastramento: http://linux-br.conectiva.com.br
Assuntos administrativos e problemas com a lista: 
            mailto:[EMAIL PROTECTED]

Responder a