Note: Due to technical difficulties, the Archives are currently not up to date.
GMANE provides an alternative service for most mailing lists. c.f. bug 424647
List Archive: gentoo-security
On Thu, Jan 08, 2004 at 05:55:26PM +0100, Frank Gruellich wrote:
> * Troy Farrell <troy@...> 8. Jan 04
> > Chain allow-icmp-traffic (2 references)
[...]
> > REJECT icmp -- anywhere anywhere
>
> The default answer of REJECT ist port unreachable. I always wondered,
> if this is a good way to answer to a question in a protocol with no
> ports. Shouldn't you answer with ICMP protocol unreachable maybe?
I thought that ICMP should never be answered with ICMP? So the
correct action would be DROP in this case.
--
gentoo-security@g.o mailing list
|
|