Don't accept RELATED packets
This commit is contained in:
parent
4f4354ba19
commit
e830037a9c
|
@ -4109,7 +4109,7 @@ function configure_firewall {
|
||||||
iptables -P INPUT DROP
|
iptables -P INPUT DROP
|
||||||
ip6tables -P INPUT DROP
|
ip6tables -P INPUT DROP
|
||||||
iptables -A INPUT -i lo -j ACCEPT
|
iptables -A INPUT -i lo -j ACCEPT
|
||||||
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
iptables -A INPUT -m conntrack --ctstate ESTABLISHED -j ACCEPT
|
||||||
|
|
||||||
# Make sure incoming tcp connections are SYN packets
|
# Make sure incoming tcp connections are SYN packets
|
||||||
iptables -A INPUT -p tcp ! --syn -m state --state NEW -j DROP
|
iptables -A INPUT -p tcp ! --syn -m state --state NEW -j DROP
|
||||||
|
|
Loading…
Reference in New Issue