]> git.ipfire.org Git - thirdparty/haproxy.git/commit
MEDIUM: tcp-act: add parameter rst-ttl to silent-drop
authorMathias Weiersmueller <mathias.weiersmueller@cyberheads.ch>
Fri, 18 Nov 2022 23:07:56 +0000 (00:07 +0100)
committerWilly Tarreau <w@1wt.eu>
Sat, 19 Nov 2022 03:53:47 +0000 (04:53 +0100)
commitd9b7174d999feba6236577e1073b93d012932703
tree3287cb024d096d6cbe9a0d8a3d68cb101821f4aa
parenta0abec8bc0f5ac547cd2ee2c7af9f7d911549c78
MEDIUM: tcp-act: add parameter rst-ttl to silent-drop

The silent-drop action was extended with an additional optional parameter,
[rst-ttl <ttl> ], causing HAProxy to send a TCP RST with the specified TTL
towards the client.

With this behaviour, the connection state on your own client-
facing middle-boxes (load balancers, firewalls) will be purged,
but the client will still assume the TCP connection is up because
the TCP RST packet expires before reaching the client.
doc/configuration.txt
src/tcp_act.c