All of lore.kernel.org
 help / color / mirror / Atom feed
* REJECT --reject-with icmp-host-unreachable vs DROP
@ 2006-03-27  8:47 Brent Clark
  2006-03-27  9:21 ` Martijn Lievaart
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Brent Clark @ 2006-03-27  8:47 UTC (permalink / raw)
  To: netfilter

Hi all

Just something I would like to pick someones brain with.

If I use the default policy of drop, BUT at the end of the chain use the following

$IPT -t filter -A FORWARD -j REJECT --reject-with icmp-host-unreachable

Would that be ok, or does is another ICMP message I can reply back with.

Reason I ask this is because I find that by using the default policy (DROP), some applications keep retrying to make a
connection etc.
Where as this approach, seems to slow things down (I stand to correction on this).

If someone could maybe help me understand this or assit I would be most grateful.

Kind Regards
Brent Clark




^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2006-03-27 15:24 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-03-27  8:47 REJECT --reject-with icmp-host-unreachable vs DROP Brent Clark
2006-03-27  9:21 ` Martijn Lievaart
2006-03-27 13:07 ` Menno Smits
2006-03-27 15:24 ` Nathaniel Hall

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.