Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: iptables REJECT types for UDP (if any)

From: Steffen Dettmer <steffen(at)dett.de>
Date: Thu Nov 28 2002 - 05:00:20 EST

If you feel a need to block traceroute, why don't block TTL exeeded but host unreachable? Did you mixed up the type 3 ICMPs, maybe? I suggest to block time-exceeded if you think you need it, but allow destination-unreachable at least for any that can be viewable, otherwise for the clients it takes long time to find out that a service isn't offered (well, I believe sometimes a connection is not an attack but a request :)).

oki,

Steffen

-- 
Dieses Schreiben wurde maschinell erstellt,
es trägt daher weder Unterschrift noch Siegel.
Received on Fri Nov 29 01:42:51 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:19 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library