All of lore.kernel.org
 help / color / mirror / Atom feed
* [LARTC] REJECTing: How and When to use What type of reply.
@ 2003-09-11 21:04 Mike Mestnik
  2003-09-11 22:08 ` Daniel Chemko
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Mike Mestnik @ 2003-09-11 21:04 UTC (permalink / raw)
  To: lartc

For this thread I'd like to FOCUS on rejecting bad traffic and not on dropping.  The first case
I'd like to discuss is where all but a handful of public web sites are allowed for ought going
connections.  A typical NAT setup is used where all the users sit behind a firewall, some have
full access to the Internet but most have restricted access.  I'd also like to bring in other
minds into the discussion, and not have it be a linux only problem.

Here is the big deal.  A web page like www.nasdaq.com is considered valid, so traffic to it's IP
208.249.117.71 is ACCEPTed.  However this site pulles content from an unknown group of other
sites, unfortunately not ACCEPTed.  In the mean time untill all the sites can be added it's not
proper to simply DROP these SYN packets.  This is where this concerns EVERYONE, the client
software needs to get the right REJECT from the firewall.  Now How and When to use What type of
reply becomes a big deal.

I'd like to open this discussion up to every one who has 2 cents and/or another good use of REJECT
vs DROP.  For my setup I have winblows computers running both IE and Netscape behind a generic
firewall *Blush*.  The two types of REJECTs I have tested are "TCP RST" and ICMP (Port
Unreachable), are there any others?

This thread may be moved to another list where appropriate.


__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software
http://sitebuilder.yahoo.com
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2003-09-11 22:47 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-09-11 21:04 [LARTC] REJECTing: How and When to use What type of reply Mike Mestnik
2003-09-11 22:08 ` Daniel Chemko
2003-09-11 22:21 ` Steve Wright
2003-09-11 22:47 ` Mike Mestnik

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.