security precautionswith iptables?

Gregory Nowak greg at romuald.net.eu.org
Sun May 20 17:26:31 EDT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

That's the whole point of that rule, to drop incoming pings. As for
the outgoing pings, that depends on how your outgoing chain is setup,
or possibly on if your ISP is blocking outgoing pings or not.

Greg


On Sun, May 20, 2007 at 09:34:43AM -0600, Littlefield, Tyler wrote:
> Hello list,
> I've been told to block ping requests with iptables. I made the following rule:
> iptables -A INPUT -p icmp --icmp-type echo-request -j DROP
> The only problem with this, is it drops all pings incoming as well, which causes a slight problem.
> Any way around this?
> Also, is there anything else that can be done in order to make the system more secure? I was told to block fragmented packets. I know what they are, but don't know enough about tcp in order to be able to do much with them.
> Help is appriciated.
> Thanks,
> _______________________________________________
> Speakup mailing list
> Speakup at braille.uwo.ca
> http://speech.braille.uwo.ca/mailman/listinfo/speakup

- -- 
web site: http://www.romuald.net.eu.org
gpg public key: http://www.romuald.net.eu.org/pubkey.asc
skype: gregn1
(authorization required, add me to your contacts list first)

- --
Free domains: http://www.eu.org/ or mail dns-manager at EU.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGUL0H7s9z/XlyUyARAtqeAKCySG6Y7JbL9+QvUObLt2KbQjd3rQCfUxhU
l/Y0fZcCAK6Wcezz3860sfI=
=JqQX
-----END PGP SIGNATURE-----




More information about the Speakup mailing list