Answer the question
In order to leave comments, you need to log in
iptables. What are the required icmp-types?
Good morning. I'm interested in the question: is it necessary to add any vital --icmp-type for the system? I also accept comments about my rules.
iptables -F
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -p tcp -m multiport --dport 22,80 -j ACCEPT
iptables -A INPUT -p icmp --icmp-type 8 -j ACCEPT
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
iptables -A OUTPUT -m conntrack --ctstate NEW,ESTABLISHED,RELATED -j ACCEPT
Answer the question
In order to leave comments, you need to log in
On ICMP types, a good dock with a description of linuxru.org/linux/55
Personally, I allow entry 3,8,12
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question