Hi, >Why would you want to optimize DROP? Do you DROP more packets than you ACCEPT?
Yes. The poor servers behind the firewall gets flooded/DDoSed now and then, so it's a very important use-case for me. The DROP rule I wrote would block a DNS Amplification attack. Best regards, Stefan Behte
<<winmail.dat>>
------------------------------------------------------------------------------ Android is increasing in popularity, but the open development platform that developers love is also attractive to malware creators. Download this white paper to learn more about secure code signing practices that can help keep Android apps secure. http://pubads.g.doubleclick.net/gampad/clk?id=65839951&iu=/4140/ostg.clktrk
_______________________________________________ Shorewall-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-devel
