Re: DROP

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Jason Opperisano wrote:
On Mon, Apr 18, 2005 at 07:37:22AM +0200, Brent Clark wrote:

I was wondering, if was adviseable to set the default policy for tables nat and mangle to DROP.

no. *all* packets traverse the filter chains--do your filtering there.

Just to better understand, don't all packets also pass the mangle table and only the first packet of a connection the nat table?


Thanks for your enlightenment...

sjm


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux