Re: iptables

From: Anders Larsen (a.larsen@identecsolutions.de)
Date: 01/30/03


From: "Anders Larsen" <a.larsen@identecsolutions.de>
Date: Thu, 30 Jan 2003 16:17:03 +0100

Kasper Dupont wrote:

> But in all cases a plain DROP is not going to work as well as
> a plain REJECT --reject-with tcp-reset. There are some reasons
> why it is a good idea to use reset:
>
> 3) It will make spoofing your IP address in a blind attack
> harder for the attacker.

Why? Please elaborate.

Cheers
 Anders