LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 04-19-2008, 05:08 AM   #1
Smokey
Member
 
Registered: Jul 2004
Distribution: Slackware
Posts: 313

Rep: Reputation: 30
Dropping RST packets with IPFW


I've been reading the IPFW manpage but it is cryptic and hard to understand. I've been trying to create a rule like this:

iptables -A INPUT -p tcp -dport $CLIENT_PORT# -tcp-flags RST RST -j DROP

Would this be the IPFW equivalent?

ipfw add 00042 drop tcp from any to any in tcpflags rst src-port $CLIENT_PORT#
 
Old 04-19-2008, 12:27 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
That looks correct to me, based on what I read in ipfw(8). Wouldn't it be quicker to test this rule than ask here?

(Also, I'm curious why you want to block RST packets.)
 
Old 04-19-2008, 12:48 PM   #3
Smokey
Member
 
Registered: Jul 2004
Distribution: Slackware
Posts: 313

Original Poster
Rep: Reputation: 30
I want to drop ISP traffic shaping RST packets. But I think it would be better to block the ISP range than the port, I think I'm setting myself up for trouble since it would block legit RST packets and I would have to wait for a TCP reconnection. I did test it but there is no difference, which led me to ask if I am doing it correctly?
 
Old 04-19-2008, 02:57 PM   #4
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
How did you test? I notice nmap(1) has a --scanflags option to allow you to specify, e.g. a TCP RST flag.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Kernel dropping packets... LWillmann Linux - Networking 1 05-25-2006 10:19 AM
dropping and forwarding packets using libpcap escorp Linux - Networking 2 04-08-2006 08:18 PM
RST Packets Pastorino Linux - Security 1 08-11-2004 03:01 PM
Dropping Network Packets Micah Linux - Networking 4 03-14-2004 09:39 PM
dropping packets ? jb_li Programming 7 04-14-2003 11:18 AM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 10:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration