public inbox for speakup@linux-speakup.org
 help / color / mirror / Atom feed
From: Gregory Nowak <greg@romuald.net.eu.org>
To: "Speakup is a screen review system for Linux." <speakup@braille.uwo.ca>
Subject: Re: security precautionswith iptables?
Date: Sun, 20 May 2007 14:26:31 -0700	[thread overview]
Message-ID: <20070520212631.GB21464@localhost.localdomain> (raw)
In-Reply-To: <000f01c79af4$9917f3d0$6501a8c0@GRANDMA>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

That's the whole point of that rule, to drop incoming pings. As for
the outgoing pings, that depends on how your outgoing chain is setup,
or possibly on if your ISP is blocking outgoing pings or not.

Greg


On Sun, May 20, 2007 at 09:34:43AM -0600, Littlefield, Tyler wrote:
> Hello list,
> I've been told to block ping requests with iptables. I made the following rule:
> iptables -A INPUT -p icmp --icmp-type echo-request -j DROP
> The only problem with this, is it drops all pings incoming as well, which causes a slight problem.
> Any way around this?
> Also, is there anything else that can be done in order to make the system more secure? I was told to block fragmented packets. I know what they are, but don't know enough about tcp in order to be able to do much with them.
> Help is appriciated.
> Thanks,
> _______________________________________________
> Speakup mailing list
> Speakup@braille.uwo.ca
> http://speech.braille.uwo.ca/mailman/listinfo/speakup

- -- 
web site: http://www.romuald.net.eu.org
gpg public key: http://www.romuald.net.eu.org/pubkey.asc
skype: gregn1
(authorization required, add me to your contacts list first)

- --
Free domains: http://www.eu.org/ or mail dns-manager@EU.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGUL0H7s9z/XlyUyARAtqeAKCySG6Y7JbL9+QvUObLt2KbQjd3rQCfUxhU
l/Y0fZcCAK6Wcezz3860sfI=
=JqQX
-----END PGP SIGNATURE-----


  reply	other threads:[~ UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
 Littlefield, Tyler
 ` Gregory Nowak [this message]
 ` Travis Siegel
   ` Igor Gueths
     ` Littlefield, Tyler

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20070520212631.GB21464@localhost.localdomain \
    --to=greg@romuald.net.eu.org \
    --cc=speakup@braille.uwo.ca \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).