From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: More neqbie questions
Date: Mon, 2 Aug 2004 20:03:54 +0100 [thread overview]
Message-ID: <200408022003.54833.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <410E7DFB.9000505@mail.co.gilchrist.fl.us>
On Monday 02 August 2004 6:46 pm, Eric Ellis wrote:
> This is one of those things that's been hounding me for the past few
> weeks that I can't understand what's *exactly* going on...
>
> I've been using the IPTables tutorial from
> http://iptables-tutorial.frozentux.net/chunkyhtml/index.html, as has
> been pointed out and recommended by many of the list's pros. It's a
> great tutorial, and I highly recommend it.
>
> However, I have either glossed something covered in it, or I have a
> fundamental misunderstanding of some part of IPTables.
>
> I know that the route works. I've verified it. I can move IPTraffic
> when I set all of my policies on my filter script to accept. However,
> when I set my policies on my script to drop, Nothing talks any more.
My recommendation is to put a LOG rule at the end of each chain, just before
the default DROP policy takes effect, and you'll see what packets are getting
that far and then being lost.
Regards,
Antony.
--
If J. Random Websurfer clicks on a button that promises dancing pigs on his
computer monitor, and instead gets a hortatory message describing the
potential dangers of the applet - he's going to choose dancing pigs over
computer security any day. If the computer prompts him with a warning screen
like: "The applet DANCING PIGS could contain malicious code that might do
permanent damage to your computer, steal your life's savings, and impair your
ability to have children," he'll click "OK" without even reading it. Thirty
seconds later he won't even remember that the warning screen even existed.
- Bruce Schneier "Secrets and Lies"
Please reply to the list;
please don't CC me.
next prev parent reply other threads:[~2004-08-02 19:03 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-08-02 17:46 More neqbie questions Eric Ellis
2004-08-02 19:03 ` Antony Stone [this message]
2004-08-02 19:50 ` Eric Ellis
2004-08-02 20:02 ` Antony Stone
2004-08-02 20:08 ` Antony Stone
-- strict thread matches above, loose matches on Subject: below --
2004-08-02 18:16 Jason Opperisano
2004-08-02 20:09 Jason Opperisano
2004-08-02 23:57 Jason Opperisano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200408022003.54833.Antony@Soft-Solutions.co.uk \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox