-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Tom Eastep wrote:

>>>
>>>Would there be a way to implicitly define such a rule, so it does not
>>>get amiss anymore.
>
>
> I suppose we could consider adding some ICMP rules to the Drop and
> Reject common actions.

The code in CVS projects Shorewall2 and LrpN now accepts ICMP 3 code 4
(fragmentation needed) and ICMP 11 (TTL exceeded) in both the Reject and
Drop chains.

- -Tom
- --
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFBZdvEO/MAbZfjDLIRAmSUAJ95XJPF8KVmqbC7Xo7yzllIa6JH3ACeJUZq
UimeCY7MA9oYGvwnuCPAEQk=
=C1Gj
-----END PGP SIGNATURE-----


-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to