My input policy is to drop all traffic unless it's part of an established connection or related to one.
Code:
iptables -P INPUT DROP
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
but if an application makes a broadcast, and something responds directly to the broadcast, the incoming packet is marked as forming a new connection (i tested this with rules such as
Code:
iptables -A INPUT -m state --state NEW -j LOG --log-prefix "NEW: "
for each of the different states and a response to a broadcast is being marked with "NEW: ")
How can i allow responses to broadcasts to enter without removing my policy of "only allow what i start"?
Bookmarks