Quote:
Originally Posted by Aeterna
I would use DROP instead of REJECT
iptables -A INPUT -m iprange --src-range 10.0.0.0-10.40.0.0 -j DROP
on target IP
|
For incoming connections yes, DROP is likely better. For locally initiated outgoing connections -- which is what OP was asking about -- I prefer
-j REJECT and
--reject-with icmp-admin-prohibited