Netfilter Rule Assistance Needed

MonMotha monmotha at indy.rr.com
Thu Dec 20 14:01:22 PST 2001


iptables -A FORWARD -p icmp -d <win2k box> --icmp-type port-unreachable 
-j DROP

Side affects would include traceroutes not working and UDP "connection" 
attempts that fail not receiving an error so they would hang until the 
application times it out.

--MonMotha

Warren Togami wrote:

> http://www.valhallalegends.com/Win2KUDPDeath.htm
> 
> This guy describes a bug in the TCP/IP stack of Windows 2000 that causes
> some programs (like Starcraft) to drop network connections when it receives
> erroneous ICMP port unreachable errors.  I think my Win2000 box is suffering
> from this bug.
> 
> Anyone know how to make Netfilter rule to block this type of incoming packet?
> 
> Would there be any negative side effects to blocking these packets besides
> PING not working entirely properly?
> 
> 
> 
> 
> ---
> You are currently subscribed to luau as: obi-wan at starwarsfan.com
> To unsubscribe send a blank email to $subst('Email.Unsub')
> 
> 



More information about the LUAU mailing list