From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Peter Marshall" Subject: DROP or REJECT Date: Tue, 11 May 2004 10:45:57 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <163801c4375e$49bb6d50$49caa8c0@caris.priv> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_1635_01C43745.24670960" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_1635_01C43745.24670960 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Which is better (to drop or reject packets)? I am asking more = specifically for connections from the internet to my external firewall. My second question is if I have a DNS in my DMZ (contains only ip's in = my dmz. internal boxes use this as their DNS. This DNS falls back to = my ISP), do I have to allow both TCP and UDP connections on port 53 ? = Can I not just have UDP, or does it use both ?=20 Thank you. Peter Marshall, BCS Projects Division, CARIS=20 115 Waggoners Lane, Fredericton NB, E3B 2L4 CANADA Phone: (506) 458-8533 (Reception)=20 ------=_NextPart_000_1635_01C43745.24670960 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Which is better (to drop or reject = packets)? =20 I am asking more specifically for connections from the internet to my = external=20 firewall.
 
My second question is if I have a DNS = in my DMZ=20 (contains only ip's in my dmz.  internal boxes use this as their = DNS. =20 This DNS falls back to my ISP), do I have to allow both TCP and UDP = connections=20 on port 53 ?  Can I not just have UDP, or does it use both ? =
 
Thank you.
 
 
 
 
Peter Marshall, BCS
Projects = Division, CARIS=20
115 Waggoners Lane, Fredericton NB, E3B 2L4 CANADA
Phone:  = (506)=20 458-8533 (Reception)
</html>
------=_NextPart_000_1635_01C43745.24670960--