LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-31-2014, 05:21 AM   #1
vasukolli
LQ Newbie
 
Registered: Dec 2014
Posts: 1

Rep: Reputation: Disabled
Is it necessary to add rules for blocking (syn,xmas, null) packets in vps server?


Hello,

I have configured firewalld to zone drop. I need to know whether i should add rules to block syn,xmas,null packets or not,because i have already set to drop zone.

Thank in advance.
 
Old 01-01-2015, 04:34 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by vasukolli View Post
I need to know whether i should add rules to block syn,xmas,null packets or not
Your question should have started by doing researching into what the characteristics are of Null and X-Mas scans. Then you should have asked yourself (or even prove empirically by watching traffic) if there are situations where traffic legitimately has no (Null) or all (X-Mas) flags set on packets. The other thing to research is the "new not SYN" situation (not sure how one would get to that themselves except for encountering it or reading much). Finally you can (log and) test if Netfilter already drops everything when "-j DROP" rules are used, is your answer.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is there a way to route packets via VPS server to the main server? Vita Linux - Networking 5 05-16-2014 10:22 AM
[SOLVED] VPS server possibly locked after adding non-adequate iptables rules warez74 Linux - Security 4 04-14-2013 11:13 AM
(for XMAS) table game ideas and instructions/rules titanium_geek General 0 12-20-2006 03:29 AM
syn packets crash88 Linux - Networking 2 07-02-2006 06:17 AM
syn packets badlya Linux - Security 3 04-24-2004 04:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration