Re: iptables why rejects this output?

2019-10-08 Thread BAGI Ákos

I figured out, the packet is INVALID.
I have absolutly no idea how can it happen.

2019.10.07 23:29 keltezéssel, Reco írta:

Hi.

On Mon, Oct 07, 2019 at 10:55:53PM +0200, BAGI Ákos wrote:

you mean I should make the firewall settings public?
good idea :)

If your security depends on obscurity, you do not have a security in the
first place.

Your INPUT rules can be probed.
Your FORWARD rules aren't relevant to your problem.
Your OUTPUT rules are, and they do nothing to protect you from the
hostile Internet.

So if you're asking why a certain iptables rule produces a
certain kernel output - please provide the offending rule at least.
Or better - full OUTPUT chain.

Reco







Re: iptables why rejects this output?

2019-10-07 Thread Reco
Hi.

On Mon, Oct 07, 2019 at 10:55:53PM +0200, BAGI Ákos wrote:
> you mean I should make the firewall settings public?
> good idea :)

If your security depends on obscurity, you do not have a security in the
first place.

Your INPUT rules can be probed.
Your FORWARD rules aren't relevant to your problem.
Your OUTPUT rules are, and they do nothing to protect you from the
hostile Internet.

So if you're asking why a certain iptables rule produces a
certain kernel output - please provide the offending rule at least.
Or better - full OUTPUT chain.

Reco



Re: iptables why rejects this output?

2019-10-07 Thread BAGI Ákos

you mean I should make the firewall settings public?
good idea :)


2019.10.05 12:32 keltezéssel, deloptes írta:

BAGI Ákos wrote:


How can I enable it with iptables? (I have lot of iptables rules).
Is it ok, to enable  it?

without the iptables rules it is hard to tell - post the rules
(iptables-save)








Re: iptables why rejects this output?

2019-10-05 Thread deloptes
BAGI Ákos wrote:

> How can I enable it with iptables? (I have lot of iptables rules).
> Is it ok, to enable  it?

without the iptables rules it is hard to tell - post the rules
(iptables-save)