Linux Netfilter discussions
 help / color / mirror / Atom feed
* RE: is it possible to block ip packets that contains experimental tcp options ?
@ 2007-05-17 17:18 Marc Cozzi
  2007-05-17 17:25 ` is it possible to block ip packets that contains experimentaltcp " Paul Blondé
  2007-05-21 11:32 ` is it possible to block ip packets that contains experimental tcp " Glenn Terjesen
  0 siblings, 2 replies; 9+ messages in thread
From: Marc Cozzi @ 2007-05-17 17:18 UTC (permalink / raw)
  To: netfilter

 Paul,

I believe that's correct. Although I'm still not
Sure what was originally meant by "experimental tcp options".

  -marc

> -----Original Message-----
> From: Paul Blondé [mailto:jpb@entel.ca] 
> Sent: Thursday, May 17, 2007 11:09 AM
> To: netfilter@lists.netfilter.org
> Subject: RE: is it possible to block ip packets that contains 
> experimentaltcp options ?
> 
> I assume that LOG-AND-DROP is your own chain, crafted so that 
> you can perform both functions with a single entry?
> 
> 
> 
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> Paul Blondé
>  
> 
> 
> > -----Original Message-----
> > From: netfilter-bounces@lists.netfilter.org
> > [mailto:netfilter-bounces@lists.netfilter.org] On Behalf Of 
> Marc Cozzi
> > Sent: Wednesday, May 16, 2007 5:19 AM
> > To: netfilter@lists.netfilter.org
> > Subject: RE: is it possible to block ip packets that contains 
> > experimentaltcp options ?
> > 
> > 
> > 
> > Glenn,
> > 
> > Not sure what you mean by "experimental" however, there are some 
> > conditions of flags that should never occur on the network. 
> These can 
> > be trapped with rules similar to the following.
> > 
> > iptables -A BLOCKED -m state --state INVALID -j 
> LOG-AND-DROP iptables 
> > -A BLOCKED -p tcp --tcp-flags ALL ALL -j LOG-AND-DROP iptables -A 
> > BLOCKED -p tcp --tcp-flags ALL NONE -j LOG-AND-DROP
> > 
> >   --marc
> > 
> > 
> > > -----Original Message-----
> > > From: Glenn Terjesen [mailto:glenn@webcat.no]
> > > Sent: Wednesday, May 16, 2007 5:24 AM
> > > To: netfilter@lists.netfilter.org
> > > Subject: is it possible to block ip packets that contains 
> > > experimental tcp options ?
> > > 
> > > Hello,
> > > got a iptables firewall filtering our servers.
> > > 
> > > Is it possible to block tcp packets that contains 
> experimental tcp 
> > > options ?
> > > 
> > > AND is it smart to do so ?
> > > 
> > > 
> > > --
> > > Mvh Glenn Terjesen @ Webcat AS
> > > Tlf: +47 37 02 20 20
> > > E-post: support@webcat.no
> > > 
> > 
> 
> 


^ permalink raw reply	[flat|nested] 9+ messages in thread
* RE: is it possible to block ip packets that contains experimental tcp options ?
@ 2007-05-16 12:18 Marc Cozzi
  2007-05-16 18:04 ` Jan Engelhardt
  0 siblings, 1 reply; 9+ messages in thread
From: Marc Cozzi @ 2007-05-16 12:18 UTC (permalink / raw)
  To: netfilter


Glenn,

Not sure what you mean by "experimental" however, there are
some conditions of flags that should never occur on the
network. These can be trapped with rules similar to the following.

iptables -A BLOCKED -m state --state INVALID -j LOG-AND-DROP
iptables -A BLOCKED -p tcp --tcp-flags ALL ALL -j LOG-AND-DROP
iptables -A BLOCKED -p tcp --tcp-flags ALL NONE -j LOG-AND-DROP

  --marc


> -----Original Message-----
> From: Glenn Terjesen [mailto:glenn@webcat.no] 
> Sent: Wednesday, May 16, 2007 5:24 AM
> To: netfilter@lists.netfilter.org
> Subject: is it possible to block ip packets that contains 
> experimental tcp options ?
> 
> Hello,
> got a iptables firewall filtering our servers.
> 
> Is it possible to block tcp packets that contains 
> experimental tcp options ?
> 
> AND is it smart to do so ?
> 
> 
> --
> Mvh Glenn Terjesen @ Webcat AS
> Tlf: +47 37 02 20 20
> E-post: support@webcat.no
> 


^ permalink raw reply	[flat|nested] 9+ messages in thread
* is it possible to block ip packets that contains experimental tcp options ?
@ 2007-05-16  9:23 Glenn Terjesen
  0 siblings, 0 replies; 9+ messages in thread
From: Glenn Terjesen @ 2007-05-16  9:23 UTC (permalink / raw)
  To: netfilter

Hello,
got a iptables firewall filtering our servers.

Is it possible to block tcp packets that contains experimental tcp
options ?

AND is it smart to do so ?


-- 
Mvh Glenn Terjesen @ Webcat AS
Tlf: +47 37 02 20 20
E-post: support@webcat.no


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2007-05-22  8:58 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-05-17 17:18 is it possible to block ip packets that contains experimental tcp options ? Marc Cozzi
2007-05-17 17:25 ` is it possible to block ip packets that contains experimentaltcp " Paul Blondé
2007-05-21 11:32 ` is it possible to block ip packets that contains experimental tcp " Glenn Terjesen
2007-05-21 11:55   ` Glenn Terjesen
2007-05-21 18:27   ` Pascal Hambourg
2007-05-22  8:58     ` Glenn Terjesen
  -- strict thread matches above, loose matches on Subject: below --
2007-05-16 12:18 Marc Cozzi
2007-05-16 18:04 ` Jan Engelhardt
2007-05-16  9:23 Glenn Terjesen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox