1 |
On Thu, Jan 08, 2004 at 05:55:26PM +0100, Frank Gruellich wrote: |
2 |
> * Troy Farrell <troy@×××××××××××.com> 8. Jan 04 |
3 |
> > Chain allow-icmp-traffic (2 references) |
4 |
|
5 |
[...] |
6 |
|
7 |
> > REJECT icmp -- anywhere anywhere |
8 |
> |
9 |
> The default answer of REJECT ist port unreachable. I always wondered, |
10 |
> if this is a good way to answer to a question in a protocol with no |
11 |
> ports. Shouldn't you answer with ICMP protocol unreachable maybe? |
12 |
|
13 |
I thought that ICMP should never be answered with ICMP? So the |
14 |
correct action would be DROP in this case. |
15 |
|
16 |
-- |
17 |
gentoo-security@g.o mailing list |