On Wed, 30 Nov 2005 22:17:25 +0100, EricT wrote:
>>>iptables -A INPUT -i eth0 -m state --state ESTABLISHED -j ACCEPT
>>
>>
>> I would leave in the RELATED also
>
> why would you? Incoming RELATED packets are only needed for special
> services such as ftp or a service hosted by the own network and these
> should be handled by its own and the appropriate rules.
FTP is handled by ip_conntrack_ftp. IRC is handled by ip_conntrack_irc.
This is because they are 2 of the most popular one. I'm sure there are
more out there and without having the Related in State you are going to
have a problem. But, hey it's your machine and you can do as you please.
It's just I don't have the time to troubleshoot problems that could have
been avoided.
--
Regards
Robert
Smile... it increases your face value!
----== Posted via Newsfeeds.Com - Unlimited-Unrestricted-Secure Usenet News==----
http://www.newsfeeds.com The #1 Newsgroup Service in the World! 120,000+ Newsgroups
----= East and West-Coast Server Farms - Total Privacy via Encryption =----