my actual iptables inquiry

Am Fr, den 20.02.2004 schrieb Ricardo A. Vetrovec um 20:36:
> that's true
> but i read boxes, so i think maybe he are mading a small network
> IF not the case we have to construct with INPUT and OUTPUT
> the last sentence of the drop general are good? i don't remeber exactly 
> because i use /etc/sysconfig/iptables to my rules!!!!!

No, DROP is no good general rule. Even you can use for a general rule
setting the chain policy. But choosing DROP as policy you really should
set a REJECT rule as last matching rule in the chain.

Additional, already your first rule suggestions are faulty. If you use
your browser and connect to a foreign web server at port 80 your own
port is not privileged port 80 but an occasional high port.


