[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: nft newbie



Am Tue, 12 Jul 2022 21:17:40 +0200
schrieb <tomas@tuxteam.de>:

> That looks like a sensible strategy to me.

It isn't at all, completely blocking incoming ICMP is a very stupid
idea.

ICMP is used for control messages, e.g. for Path MTU discovery.
The only IMCP message that can be blocked is echo request or echo
reply, everything else creates problems like nasty timeouts to certain
sites.
You can block incoming echo requests and let all others through it.


Reply to: