|
|
|
|
|
by huhtenberg
101 days ago
|
|
Sanity checks, sure, but SYN,!ACK packets cannot be rejected before the conntrack for obvious reasons. > Plenty of setups block incoming SYN,!ACK packets Nowhere close to being "plenty". It's doable, but this is extremely niche. |
|
I can't really imagine why you would do it for NAT'd v4 since you can't avoid the connection tracking overhead, but you certainly could, and I don't doubt OP has run into it in the wild. I've seen much weirder firewall rules :)