Re: ip6tables icmp conntracking on 2.6.18 vs 2.6.24

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



also sprach Petr Pisar <petr.pisar@xxxxxxxx> [2008.04.02.2344 +0200]:
> ICMPv6 is used for neighborhood discovery (similar to ARP in IPv4).
> Therefore droping all new packets is bad idea because it will drop ND
> requestes from other link local stations.

This is just a test-case, really. I am aware that I need to open the
filter for more ICMP types. But in this case, it's all about
echo-reply not being treated as RELATED...



also sprach Jan Engelhardt <jengelh@xxxxxxxxxxxxxxx> [2008.04.02.2357 +0200]:
> Even so, it should not be INVALID but NEW.

Right, except RELATED in this case... but I understand your reply
was to Petr.

-- 
martin | http://madduck.net/ | http://two.sentenc.es/
 
"durch frauen werden die höhepunkte des lebens bereichert
 und die tiefpunkte vermehrt."
                                                 - friedrich nietzsche
 
spamtraps: madduck.bogus@xxxxxxxxxxx

Attachment: digital_signature_gpg.asc
Description: Digital signature (see http://martin-krafft.net/gpg/)


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux