Thursday, December 25, 2014

Iptables rules , Drop or Reject?

By Default, Pinging is fine to both yahoo.com and Google.com

image

If we turn on the firewall, to Drop icmp to google, and Reject UDP to yahoo.com

image

then ping google by ip which is rejected by firewall policy

image

What about TCP

image

SO, Drop means pretend the port is not open, which is like a implicit denial .

Reject means explicit denial.

No comments:

 
Locations of visitors to this page