Re: How to drop existing connections

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



В Пнд, 07/04/2008 в 02:05 -0700, Vitaly пишет:
> --- Karim Asif <karimas@xxxxxxxxxxxx> wrote:
> 
> > Using iptables?
> > just add a drop rule having src/dest ip addressess
> > and ports and protocol on
> > top of other rules.
> 
> Probably I wasn't clear - I want to kill existing,
> already opened connection. 
> Now, after reading some articles/threads, it seems
> that only utils like tcpkill, cutter can do this...

You can use conntrack utility to remove conntrack entry, if you also
drop INVALID packets with iptables this will let you kill connection.

> > 
> > ----- Original Message ----- 
> > From: "Vitaly" <vitaly_il@xxxxxxxxx>
> > To: <netfilter@xxxxxxxxxxxxxxx>
> > Sent: Monday, April 07, 2008 11:30 AM
> > Subject: How to drop existing connections
> > 
> > 
> > > I'd like to kill all existing connections to the
> > > specific IP/port. What is the simpliest way to do
> > > this?
> > >
> > > Thanks,
> > > Vitaly
> > >
> > >
> > > 
> > >
> >
> ____________________________________________________________________________________
> > > You rock. That's why Blockbuster's offering you
> > one month of Blockbuster 
> > > Total Access, No Cost.
> > > http://tc.deals.yahoo.com/tc/blockbuster/text5.com
> > > --
> > > To unsubscribe from this list: send the line
> > "unsubscribe netfilter" in
> > > the body of a message to majordomo@xxxxxxxxxxxxxxx
> > > More majordomo info at 
> > http://vger.kernel.org/majordomo-info.html 
> > 
> > 
> 
> 
> 
>       ____________________________________________________________________________________
> You rock. That's why Blockbuster's offering you one month of Blockbuster Total Access, No Cost.  
> http://tc.deals.yahoo.com/tc/blockbuster/text5.com
> --
> To unsubscribe from this list: send the line "unsubscribe netfilter" in
> the body of a message to majordomo@xxxxxxxxxxxxxxx
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
-- 
Покотиленко Костик <casper@xxxxxxxxxxxx>

--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux