tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: ipf: interaction of "in" and "out" rules



On Fri, 24 Jul 2015 14:00:00 +0200, Edgar Fuß wrote:
> If I have a (non-quick) ipf rule blocking a packet on the incoming side, 
> will a rule on the outgoing side "see" that packet, i.e., is it possible
> to over-rule the "block in" decision with a "pass out" rule?

If you have the "pass out" rule keep state, then yes, since the 
incoming response will be recognized as belonging to this same stateful 
connection.

Otherwise, no.

hauke

-- 
Hauke Fath                        <hauke%Espresso.Rhein-Neckar.DE@localhost>
Ernst-Ludwig-Straße 15
64625 Bensheim
Germany


Home | Main Index | Thread Index | Old Index