On 28/12/2013 5:03 p.m., Nyamul Hassan wrote: > Thank you all for your responses! > > This is setup as a forward transparent proxy for an ISP. Most of the RST > packets are targeted towards remote IPs (not the ISP users). > > Although we do not see any detrimental effect on Squid functioning in our > setup, would you recommend that we stop blocking these in iptables? I would expect it is a good idea to let these packets go through, yes. Amos