All of lore.kernel.org
 help / color / mirror / Atom feed
* Filtering in PREROUTING
@ 2007-01-17 21:38 george
  2007-01-17 22:17 ` Jorge Davila
                   ` (5 more replies)
  0 siblings, 6 replies; 20+ messages in thread
From: george @ 2007-01-17 21:38 UTC (permalink / raw)
  To: netfilter

I've seen a few places telling me that you shouldn't filter in the
mangle table.  However, it seems sensible to me to drop junk packets in
PREROUTING rather than have to duplicate those rules in both INPUT and
FORWARD.

Having done this, I'm seeing packets dropped as invalid when I would
expect them to be OK (but most traffic is behaving as expected).  Before
I start digging into this I want to check if filtering in the mangle
table really is stupid.

Can anyone explain this to me, or point me somewhere that will tell me
please.  I haven't found anything other than a simple statement
anywhere.

Thanks,
George.



^ permalink raw reply	[flat|nested] 20+ messages in thread

end of thread, other threads:[~2007-01-20  2:23 UTC | newest]

Thread overview: 20+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-01-17 21:38 Filtering in PREROUTING george
2007-01-17 22:17 ` Jorge Davila
2007-01-18  2:01   ` Grant Taylor
2007-01-18  8:42     ` Alexandru Dragoi
2007-01-19 17:34       ` R. DuFresne
2007-01-18  8:46     ` george
2007-01-19 17:25     ` R. DuFresne
2007-01-18  4:44 ` p0f patch Tim Heagarty
2007-01-19 19:23   ` Tim Heagarty
2007-01-20  2:23     ` Michael Rash
2007-01-18 10:52 ` Filtering in PREROUTING Georgi Alexandrov
2007-01-19 10:19   ` george
2007-01-19 11:32     ` Pascal Hambourg
2007-01-18 14:25 ` Grant Taylor
2007-01-19 13:17   ` george
2007-01-18 14:57 ` Filtering in PREROUTING --- Some random thoughts / points Grant Taylor
2007-01-19 17:54   ` R. DuFresne
2007-01-18 19:19 ` Filtering in PREROUTING Pascal Hambourg
2007-01-19 13:17   ` george
2007-01-19 15:51     ` Grant Taylor

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.