Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: IPChains rules
- To: Tobias Diedrich <ranma@example.com>
- Subject: Re: IPChains rules
- From: "Stephen J. Turnbull" <turnbull@example.com>
- Date: Sat, 3 Mar 2001 14:35:12 +0900
- Cc: <tlug@example.com>
- Content-Transfer-Encoding: 7bit
- Content-Type: text/plain; charset=us-ascii
- In-Reply-To: <Pine.LNX.4.30.0103021737080.4103-100000@example.com>
- References: <15007.28049.271756.892269@example.com><Pine.LNX.4.30.0103021737080.4103-100000@example.com>
- Reply-To: tlug@example.com
- Resent-From: tlug@example.com
- Resent-Message-ID: <FCYb3B.A.S3C.9PIo6@example.com>
- Resent-Sender: tlug-request@example.com
>>>>> "Tobias" == Tobias Diedrich <ranma@example.com> writes: Tobias> AFAIK No. At least not the "Allow only known existing Tobias> incoming connections" part. You need to know the State of Tobias> the Connection for that. Ah, OK. You _can_ ignore connection attempts on TCP ports, I thought that was what you meant. It's not clear what the benefit of this is to me yet; I guess you can use it to block garbage at the router? Or is it just more efficient to drop the packets on the floor early rather than drop them on the floor because the listener never sees a SYN? Tobias> Works for ping, traceroute, Wrong. Ping is ICMP, traceroute is UDP. No state ... sorry. If RELATED means what I think it does, it's just a guess. It could be (easily) spoofed; (conventional) ping and traceroute packets don't contain any information that would help you to verify this status. I wonder how much checking is done on ESTABLISHED, for that matter. Is it just a dynamic firewall that automatically opens an incoming window to the local source port when you make an outgoing connection? Or does it verify TCP serial numbers and (maybe) high-level protocol? Seems unlikely.... Tobias> http, ftp. Or is FTP's "two-circuit" protocol what is meant by "RELATED"? -- University of Tsukuba Tennodai 1-1-1 Tsukuba 305-8573 JAPAN Institute of Policy and Planning Sciences Tel/fax: +81 (298) 53-5091 _________________ _________________ _________________ _________________ What are those straight lines for? "XEmacs rules."
- Follow-Ups:
- Re: IPChains rules
- From: Tobias Diedrich <ranma@example.com>
- References:
- Re: IPChains rules
- From: "Stephen J. Turnbull" <turnbull@example.com>
- Re: IPChains rules
- From: Tobias Diedrich <ranma@example.com>
Home | Main Index | Thread Index
- Prev by Date: Re: IPChains rules
- Next by Date: Re: IPChains rules
- Prev by thread: Re: IPChains rules
- Next by thread: Re: IPChains rules
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links