Fw: How to remove Established Connection

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Friday 11 October 2002 3:03 pm, HareRam wrote:

> Hi all
> thanks its working using my own methods,
> but idea is lot of people, especially Mr Antony's
>
> what is the Recomended DROP or REJECT
> just now my Rule is work with DROP
>
> but i saw now here REJECT
> which one is powerfull to use to disable connections of Forward

I recommend you use REJECT for internal clients (people who you want to be 
nice to, and who you don't want to get excessive delays when they try to do 
something your firewall rules don't allow).

I recommend you use DROP for external connections (people who you don't want 
to be nice to, you don't want to give any information to, and who you don't 
care whether their client hangs for 60 seconds instead of immediately saying 
"connection refused").

Antony.

-- 

This is not a rehearsal.
This is Real Life.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux