On 6/8/20 10:16 AM, Tom Eastep wrote:
> As shipped, shorewall6.conf includes 'AllowICMPs' in the
> BLACKLIST_DEFAULT, DROP_DEFAULT, and REJECT_DEFAULT settings. The
> AllowICMPs action accepts all ICMP6 packet types required by RFC 4890.

it that's sufficient, then I'm good.

atm, my shorewall(6).conf setting are exactly as spec'd at

        http://www.shorewall.net/Actions.html

> So if your net->all policy is DROP (recommended)

it is

> then your firewalls should pass those packets.

great, thx again!


_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to