From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from linserver.romuald.net.eu.org ([63.228.150.209]) by speech.braille.uwo.ca with esmtp (Exim 3.36 #1 (Debian)) id 1Hpswa-0001oB-00 for ; Sun, 20 May 2007 17:28:00 -0400 Received: (qmail 23591 invoked by uid 1000); 20 May 2007 14:26:32 -0700 Date: Sun, 20 May 2007 14:26:31 -0700 From: Gregory Nowak To: "Speakup is a screen review system for Linux." Subject: Re: security precautionswith iptables? Message-ID: <20070520212631.GB21464@localhost.localdomain> References: <000f01c79af4$9917f3d0$6501a8c0@GRANDMA> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii; x-action=pgp-signed Content-Disposition: inline In-Reply-To: <000f01c79af4$9917f3d0$6501a8c0@GRANDMA> X-PGP-Key: http://www.romuald.net.eu.org/pubkey.asc User-Agent: Mutt/1.5.13 (2006-08-11) X-BeenThere: speakup@braille.uwo.ca X-Mailman-Version: 2.1.9 Precedence: list Reply-To: "Speakup is a screen review system for Linux." List-Id: "Speakup is a screen review system for Linux." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 20 May 2007 21:28:00 -0000 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 That's the whole point of that rule, to drop incoming pings. As for the outgoing pings, that depends on how your outgoing chain is setup, or possibly on if your ISP is blocking outgoing pings or not. Greg On Sun, May 20, 2007 at 09:34:43AM -0600, Littlefield, Tyler wrote: > Hello list, > I've been told to block ping requests with iptables. I made the following rule: > iptables -A INPUT -p icmp --icmp-type echo-request -j DROP > The only problem with this, is it drops all pings incoming as well, which causes a slight problem. > Any way around this? > Also, is there anything else that can be done in order to make the system more secure? I was told to block fragmented packets. I know what they are, but don't know enough about tcp in order to be able to do much with them. > Help is appriciated. > Thanks, > _______________________________________________ > Speakup mailing list > Speakup@braille.uwo.ca > http://speech.braille.uwo.ca/mailman/listinfo/speakup - -- web site: http://www.romuald.net.eu.org gpg public key: http://www.romuald.net.eu.org/pubkey.asc skype: gregn1 (authorization required, add me to your contacts list first) - -- Free domains: http://www.eu.org/ or mail dns-manager@EU.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGUL0H7s9z/XlyUyARAtqeAKCySG6Y7JbL9+QvUObLt2KbQjd3rQCfUxhU l/Y0fZcCAK6Wcezz3860sfI= =JqQX -----END PGP SIGNATURE-----