Re: Is this firewall good enough?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tuesday 08 June 2004 10:42 am, Feizhou wrote:

> >2.  /sbin/iptables -A INPUT -p tcp -m state --state
> >ESTABLISHED,RELATED -j ACCEPT
>
> Forget about this. It makes things easier yes but it is too slow if you
> come under attack...but then you put everything on one box seemly so I
> guess you don't get much traffic.

How do you recommend dealing with reply packets instead?

Regards,

Antony.

-- 
"The future is already here.   It's just not evenly distributed yet."

 - William Gibson

                                                     Please reply to the list;
                                                           please don't CC me.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux