Difference between revisions of "Talk:Bering-uClibc 4.x - User Guide - IPv6 Networking - Configure Shorewall6"
From bering-uClibc
Davidmbrooke (Talk | contribs) |
|||
Line 2: | Line 2: | ||
Have you seen /usr/share/shorewall6/action.AllowICMPs? It is my understanding that this called with DROP and REJECT. Do we need more? --[[User:Kapeka|Kapeka]] 10:42, 20 January 2011 (UTC) | Have you seen /usr/share/shorewall6/action.AllowICMPs? It is my understanding that this called with DROP and REJECT. Do we need more? --[[User:Kapeka|Kapeka]] 10:42, 20 January 2011 (UTC) | ||
+ | |||
+ | I had no idea that file was there! I had previously added an explicit "ACCEPT all all ipv6-icmp" in my Rules file, but I don't need that. Thanks kp (and special thanks to Tom for fixing it in the first place). Something to add to the Wiki. [[User:Davidmbrooke|Davidmbrooke]] 19:58, 20 January 2011 (UTC) |
Latest revision as of 19:58, 20 January 2011
RFC 4890 defines "Recommendations for Filtering ICMPv6 Messages in Firewalls". Would be good to have some guidelines on implementing compliance with that using Shorewall6. Davidmbrooke 21:39, 19 January 2011 (UTC)
Have you seen /usr/share/shorewall6/action.AllowICMPs? It is my understanding that this called with DROP and REJECT. Do we need more? --Kapeka 10:42, 20 January 2011 (UTC)
I had no idea that file was there! I had previously added an explicit "ACCEPT all all ipv6-icmp" in my Rules file, but I don't need that. Thanks kp (and special thanks to Tom for fixing it in the first place). Something to add to the Wiki. Davidmbrooke 19:58, 20 January 2011 (UTC)