Re: DROP

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Apr 18, 2005 at 07:37:22AM +0200, Brent Clark wrote:
> Hi all
> 
> I was wondering, if was adviseable to set the default policy for tables 
> nat and mangle to DROP.

no.  *all* packets traverse the filter chains--do your filtering
there.

this question seems to come up every so often, and the idea is
absolutely indefensible, IMHO.

-j

--
"Tom Tucker: And now time for the Ollie weather report.
 Ollie: It's gonna rain.
 Tom Tucker: Thanks Ollie."
        --Family Guy


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux