All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mike Mestnik <cheako911@yahoo.com>
To: lartc@vger.kernel.org
Subject: [LARTC] REJECTing: How and When to use What type of reply.
Date: Thu, 11 Sep 2003 21:04:21 +0000	[thread overview]
Message-ID: <marc-lartc-106331435500752@msgid-missing> (raw)

For this thread I'd like to FOCUS on rejecting bad traffic and not on dropping.  The first case
I'd like to discuss is where all but a handful of public web sites are allowed for ought going
connections.  A typical NAT setup is used where all the users sit behind a firewall, some have
full access to the Internet but most have restricted access.  I'd also like to bring in other
minds into the discussion, and not have it be a linux only problem.

Here is the big deal.  A web page like www.nasdaq.com is considered valid, so traffic to it's IP
208.249.117.71 is ACCEPTed.  However this site pulles content from an unknown group of other
sites, unfortunately not ACCEPTed.  In the mean time untill all the sites can be added it's not
proper to simply DROP these SYN packets.  This is where this concerns EVERYONE, the client
software needs to get the right REJECT from the firewall.  Now How and When to use What type of
reply becomes a big deal.

I'd like to open this discussion up to every one who has 2 cents and/or another good use of REJECT
vs DROP.  For my setup I have winblows computers running both IE and Netscape behind a generic
firewall *Blush*.  The two types of REJECTs I have tested are "TCP RST" and ICMP (Port
Unreachable), are there any others?

This thread may be moved to another list where appropriate.


__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software
http://sitebuilder.yahoo.com
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

             reply	other threads:[~2003-09-11 21:04 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-09-11 21:04 Mike Mestnik [this message]
2003-09-11 22:08 ` [LARTC] REJECTing: How and When to use What type of reply Daniel Chemko
2003-09-11 22:21 ` Steve Wright
2003-09-11 22:47 ` Mike Mestnik

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=marc-lartc-106331435500752@msgid-missing \
    --to=cheako911@yahoo.com \
    --cc=lartc@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.