All of lore.kernel.org
 help / color / mirror / Atom feed
* Prerouting question
@ 2004-04-06 18:00 Stuart Lamble
  2004-04-06 18:16 ` Antony Stone
  2004-04-06 18:21 ` Cedric Blancher
  0 siblings, 2 replies; 5+ messages in thread
From: Stuart Lamble @ 2004-04-06 18:00 UTC (permalink / raw)
  To: netfilter

Hi All

If prerouting is the first rule a packet touches when arriving at the
firewall, why then do we not set the default to DROP here and allow
through what we need.
That is if you are running a nat environment.

Then if a packet makes it through the PREROUTING, you can pass it to the
INPUT rule base if it is for the firewall machine itself or to FORWARD
if its for the LAN for example.
Making the default DROP for both the above, and allowing specifics
again.

Thanks for any comments offered...

Stuart




^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2004-04-06 18:28 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-04-06 18:00 Prerouting question Stuart Lamble
2004-04-06 18:16 ` Antony Stone
2004-04-06 18:23   ` Cedric Blancher
2004-04-06 18:28   ` Stuart Lamble
2004-04-06 18:21 ` Cedric Blancher

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.