Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #384

Re: iptables DNAT/SNAT/ICMP done right?

From buck <buck@private.mil>
Newsgroups comp.os.linux.networking
Subject Re: iptables DNAT/SNAT/ICMP done right?
Date 2011-06-24 17:45 +0000
Organization Say What?
Message-ID <iu2ifu017b2@news6.newsguy.com> (permalink)
References <itq01e$2bn$1@news.m-online.net>

Show all headers | View raw


Christian Brandt <brandtc@psi5.com> wrote in
news:itq01e$2bn$1@news.m-online.net: 

> I am uncertain about my implementations of DNAT, SNAT and the
> importance of ICMP - though I think ICMP is a good thing to have
> around in case of congestion&family.

I think you should restrict ICMP by function.

http://www.malibyte.net/iptables/scripts/fwscripts.html
has understandable info.
--
buck

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

iptables DNAT/SNAT/ICMP done right? Christian Brandt <brandtc@psi5.com> - 2011-06-21 13:41 +0200
  Re: iptables DNAT/SNAT/ICMP done right? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-21 23:42 +0200
    Re: iptables DNAT/SNAT/ICMP done right? Christian Brandt <brandtc@psi5.com> - 2011-06-24 10:39 +0200
  Re: iptables DNAT/SNAT/ICMP done right? buck <buck@private.mil> - 2011-06-24 17:45 +0000

csiph-web