From mboxrd@z Thu Jan 1 00:00:00 1970 From: Nikolai Alexandrov Subject: Re: firewall ignore the rule Date: Thu, 14 Jul 2005 18:03:03 +0300 Message-ID: <42D67EA7.6070604@gmail.com> References: <2452665f0507130352544ab556@mail.gmail.com> <1121252895.11584.6.camel@anduril.intranet.cartel-securite.net> <2452665f05071318551f788f42@mail.gmail.com> <20050714020155.GA26028@bender.817west.com> <2452665f0507131910300b00de@mail.gmail.com> <20050714021032.GA26090@bender.817west.com> <2452665f0507131919823198c@mail.gmail.com> <20050714022409.GA26148@bender.817west.com> Reply-To: netfilter@lists.netfilter.org Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-bounces@lists.netfilter.org Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii"; format="flowed" To: Ishwar Rattan Cc: netfilter@lists.netfilter.org You might want to look at this project: http://arpstar.sourceforge.net/. Ishwar Rattan wrote: >On Wed, 13 Jul 2005, Jason Opperisano wrote: > > > >>On Thu, Jul 14, 2005 at 10:19:19AM +0800, liyas_m m wrote: >> >> >>>u mean blocking the MAC address also doesnot do any good. hmm i >>>thought iptables is that powerful. >>> >>> >>it is that powerful. you are currently incapable of comprehending its >>power. >> >> > >I like the response. My suggestion would have been to rewrite the tcp/ip >stack and block them at layer 1 :-) > >-ishwar > > > >