Iptables
Should I start my script with all the DROP before ACCEPT or the other way around?
|
you accept things by exception with a default drop policy on each table. or a default drop at the very bottom of it.
|
If a connection is already accepted and it still fits the drop condition at the end of the script will it still be dropped?
|
No, iptables will stop comparing once a positive match is made. This is why you you are able to accept the things you want and then drop everything else at the end.
|
One of the members of my LUG gave a presentation about his iptables script and posted the script to the LUG wiki.
Maybe it will be a useful reference. |
Quote:
|
All times are GMT -5. The time now is 08:08 AM. |