V
V
Vladimir Solovyov2015-02-06 06:21:47
iptables
Vladimir Solovyov, 2015-02-06 06:21:47

iptables. What are the required icmp-types?

Good morning. I'm interested in the question: is it necessary to add any vital --icmp-type for the system? I also accept comments about my rules.

iptables -F
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -p tcp -m multiport --dport 22,80 -j ACCEPT
iptables -A INPUT -p icmp --icmp-type 8 -j ACCEPT
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
iptables -A OUTPUT -m conntrack --ctstate NEW,ESTABLISHED,RELATED -j ACCEPT

Answer the question

In order to leave comments, you need to log in

1 answer(s)
S
Sergey Petrikov, 2015-02-06
@Cttr

On ICMP types, a good dock with a description of linuxru.org/linux/55
Personally, I allow entry 3,8,12

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question