LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-11-2004, 09:05 AM   #1
Pastorino
Member
 
Registered: Jul 2004
Distribution: RHEL 6.2
Posts: 35

Rep: Reputation: 17
RST Packets


Is it safe to allow RST packets through the firewall?

I'm asking this because I noticed, using Logwatch, that the firewall was blocking DTP=80 packets. Which was weird at first, since I allow DPT=80 packets out. So I checked the /var/log/messages file. And the packet was like this:

Aug 10 19:03:58 kernel: FORWARD blocked: IN=eth1 OUT=eth0 SRC=x.x.x.x DST=y.y.y.y LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=38568 DF PROTO=TCP SPT=4923 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
 
Old 08-11-2004, 03:01 PM   #2
TheIrish
Member
 
Registered: Oct 2003
Location: ITALY
Distribution: Debian, Ubuntu, Fedora
Posts: 137

Rep: Reputation: 15
Well, as far as i know there shouldn't be any security issue in letting RST in and out.
The only way RST can be somehow harmful is using it as part of a stealth scan.
Two typical combos follow:
  • SYN,RST SYN,RST
  • SYN,ACK,FIN,RST RST
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How linux TCP handle (RST,SYN) at initial connection establishment syseeker Linux - Security 1 01-14-2005 04:20 PM
Repeated, targeted port 1025 ACK RST scottman Linux - Security 2 10-06-2004 01:35 AM
packets sent VS packets received fsasya Linux - Networking 0 07-18-2004 07:11 PM
encapsulating TCP packets in UDP packets... yoshi95 Programming 3 06-03-2004 02:53 PM
RH 7.3 Server infected with Linux.Jac.8759 and Linux.RST.B virus osso09 Linux - Security 10 11-17-2003 11:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration