RE: diffrence between reject & drop ?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



El mar, 01 de 02 de 2005 a las 09:47, Rob Sterenborg escribiÃ:
> netfilter-bounces@xxxxxxxxxxxxxxxxxxx wrote:
> > What is the basic diffrence between rejecting a packet & droping a
> > packet ? 
> > 
> > both denies the packet right ?
> 
> Yes, but REJECT notifies the sender that the packet was not accepted,
> DROP silently discards the packet.

What use to be advised is to use:

For TCP: REJECT --reject-with tcp-reset
For UDP: REJECT --reject-with icmp-port-unreachable
For ICMP: DROP

Regards.

-- 
Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
jkerouac@xxxxxxxxx
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÃA

The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
                -- Jack Kerouac, "On the Road"




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux