Re: lots of tcp port 445 traffic

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> > iptables -I cus2jarwan -p tcp --dport 445 -j REJECT --reject-with tcp-reset
> >
> > or
> >
> > iptables -I cus2jarwan -p tcp --dport 445 -j DROP
> >
>
> You definately don't want to use -J REJECT - this will do more harm
> than good, as it will be generating an ICMP unreachable message for
> each port 445 packet.

My mistake - I didn't notice you were using "--reject-with tcp-reset".
Pretty sure you'd be better off with DROP anyway.

Regards,
Paul


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux