[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]
Re: redhat-config-securitylevel vs redhat-config-firewall?
- From: Alan Cox <alan redhat com>
- To: fedora-test-list redhat com
- Subject: Re: redhat-config-securitylevel vs redhat-config-firewall?
- Date: Wed, 8 Oct 2003 14:43:07 -0400 (EDT)
> My understanding is that RELATED should catch and allow all ICMP error
> messages "related" to current, valid connections. This included ICMP
> "need to fragment" messages.
ICMP messages can arise from midstream routers. In that situation you can't
do useful filtering really. Its a problem for ipsec where the router is
untrusted by the security policy yet to ignore it might lose your
connection.
[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]