Re: iptables REJECT types for UDP (if any)

From: Philipp Schulte (pschulte@uni-duisburg.de)
Date: 11/17/02

  • Next message: Simon Byrnand: "RE: iptables REJECT types for UDP (if any)"
    Date: Sun, 17 Nov 2002 03:11:16 +0100
    From: Philipp Schulte <pschulte@uni-duisburg.de>
    To: focus-linux@securityfocus.com
    
    

    Miguel Angel Rodríguez Jódar wrote:

    > > using -j DROP as a target, what I want to know is what types
    > > of REJECT
    > > can be used for UDP packets? Thanks.
    >
    > AFAIK, UDP packets are not realiable

    This is misleading. UDP (as opposed to TCP) is a connection-less
    protocol. That means that UDP itself doesn't check if packets made
    their way. But this doesn't make the UDP-packets themselves less
    reliable than TCP-packets.

    > haven't got things like the RST option in their headers as TCP
    > packets have, so dropping it is your only choice.

    While it is true that UDP doesn't know such a thing as RST, dropping
    them is _not_ the only choice. The equivalent to TCP-RST would be to
    send an ICMP-PortUnreachable.
    Phil



    Relevant Pages

    • Re: tcludp - bug when closing 1-of-2 listening ports
      ... I'd say something like a zero-length UDP packet... ... It is indeed linked with zero-sized UDP packets. ... % puts -nonewline $s titi ... The zero-sized packet wreaks havoc in tcludp only if it comes on ...
      (comp.lang.tcl)
    • Re: receive delay
      ... UDP packets are used for new mail notifications, or in this case to notify ... the client is requesting the update instead of the server sending a UDP ... right of outlook, also under E-mail accounts the Use Cached mode is ... Something is blocking UDP packets. ...
      (microsoft.public.exchange.admin)
    • Re: Deaf CAsyncSocket on Windows Service.
      ... Note that for UDP, your network stack is free to discard, at any time, for any reason ... correlation between UDP packets sent and UDP packets received, ... UDP does not guarantee delivery, ... If you do a receive of fewer bytes than the UDP message, ...
      (microsoft.public.vc.mfc)
    • blocking for multiple sources
      ... One of my other threads' job is to queue up UDP packets for the main ... But occasionally I may need to have the main thread send a pulse to the ... with a timeout using select, ...
      (comp.os.qnx)
    • HTTPS Tunnel: how-to write...
      ... Our UDP packets are audio and video. ... Is a HTTPTunnel a solution that will enable us to send UDP to and ... server over port 80/433? ...
      (microsoft.public.win32.programmer.networks)