Earl A. Killian wrote:

> So then I'm asking how does anything ever get into that table, if
> incoming packets are all denied?  Are SYN packets exempted from
> -deny_incoming?


No, SYN packets aren't exempted.  Incoming packets that are associated
with a pre-existing connection (or attempt) originating from the inside
are permitted.

The other option is to set '-target_address', which would redirect such
incoming packets to a particular address.


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-net" in the body of the message

Reply via email to