On 11/01/2013 12:38 PM, Tom Eastep wrote:
> On 10/31/2013 9:39 AM, Stefan Behte wrote:
>> Hi,
>>
>> I've noticed when creating DROP rules against malicious traffic,
>> shorewall creates them in the ZONE2ZONE chain (in my example wan2dmz).
>> However, getting to the DROP entry involves several jumps between
>> chains, and happens pretty late (if I got it right).
>> ...
> Why would you want to optimize DROP? Do you DROP more packets than you
> ACCEPT?

I'm pretty sure that's the case in a lot of my routers... ;-)

------------------------------------------------------------------------------
Android is increasing in popularity, but the open development platform that
developers love is also attractive to malware creators. Download this white
paper to learn more about secure code signing practices that can help keep
Android apps secure.
http://pubads.g.doubleclick.net/gampad/clk?id=65839951&iu=/4140/ostg.clktrk
_______________________________________________
Shorewall-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-devel

Reply via email to