none <(E-Mail Removed)> writes:
> Given the various iptables icmp reject types, which is suppose to make
> the calling host shut up and go away the fastest ?
>
> It looks like it may be just doing a DROP and not wasting replying may be
> the answer because most seem to ignore the reject messages and syn away...
>
> Any experts with insight to this ?
>
> Valid reject types:
> icmp-net-unreachable ICMP network unreachable
> net-unreach alias
> icmp-host-unreachable ICMP host unreachable
> host-unreach alias
> icmp-proto-unreachable ICMP protocol unreachable
> proto-unreach alias
> icmp-port-unreachable ICMP port unreachable (default)
> port-unreach alias
> icmp-net-prohibited ICMP network prohibited
> net-prohib alias
> icmp-host-prohibited ICMP host prohibited
> host-prohib alias
> tcp-reset TCP RST packet
> tcp-rst alias
> icmp-admin-prohibited ICMP administratively prohibited (*)
> admin-prohib alias
Have you considered using tcp-reset?
--
[pl>en: Andrew] Andrzej Adam Filip :
(E-Mail Removed) :
(E-Mail Removed)
Home site:
http://anfi.homeunix.net/