On 6/8/20 10:16 AM, Tom Eastep wrote:
> As shipped, shorewall6.conf includes 'AllowICMPs' in the
> BLACKLIST_DEFAULT, DROP_DEFAULT, and REJECT_DEFAULT settings. The
> AllowICMPs action accepts all ICMP6 packet types required by RFC 4890.
it that's sufficient, then I'm good.
atm, my shorewall(6).conf setting are exactly as spec'd at
http://www.shorewall.net/Actions.html
> So if your net->all policy is DROP (recommended)
it is
> then your firewalls should pass those packets.
great, thx again!
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users