--state NEW -j DROP (would be great)
hno at marasystems.com
Wed Oct 26 07:47:36 CEST 2005
On Wed, 26 Oct 2005, Sylvan Andrew wrote:
> Could somebody please explain the 'iptables -A INPUT -eth0 -m state --state
> NEW -j DROP' a bit more for me ? I understand that it won't allow any
> outside initiated inbound connections into a network.
> However occasionally if
> I'm doing a tcpdump we see things like:
> 21:04:48.935367 IP 18.104.22.168.15378 > 22.214.171.124.4154: R 0:0(0) ack 1
> win 0
These are INVALID, not part of any connection.
So if you use
-i eth0 -m state --state NEW,INVALID -j DROP
you should see the expected result..
More information about the netfilter