Re: a new question on iptables and port 5353

2012-03-26 Thread Paul Allen Newell
Anthony, Frantisek, and Bruno: I thank you for the replies. I am going to take a pause to read up on what all of you have given me. I am still uncertain why 3535 only shows up as "Mac" when I google, but hopefully a bit more digging with your suggestions will clear that up I'll post once I a

Re: a new question on iptables and port 5353

2012-03-25 Thread Bruno Wolff III
On Sun, Mar 25, 2012 at 10:03:28 +0200, Frantisek Hanzlik wrote: and - UDP is stateless, thus no "-m state --state NEW". While the UDP protocol is stateless, for iptables UDP isn't when matching on state. A flow is tracked so that inbound UDP packets are associated with recently sent outgoi

Re: a new question on iptables and port 5353

2012-03-25 Thread Frantisek Hanzlik
Paul Allen Newell wrote: > To all: > > With help from Craig and Reindl, I've understood what happens with the > automated entry of port 631 for udp/tcp and how to rewrite to not make > it a world access (in/out) rule. Waiting for next install of F16 to test > when and how the automated entry happe

Re: a new question on iptables and port 5353

2012-03-25 Thread Anthony Messina
On 03/25/2012 12:31 AM, Paul Allen Newell wrote: > To all: > > With help from Craig and Reindl, I've understood what happens with the > automated entry of port 631 for udp/tcp and how to rewrite to not make > it a world access (in/out) rule. Waiting for next install of F16 to test > when and how t

a new question on iptables and port 5353

2012-03-24 Thread Paul Allen Newell
To all: With help from Craig and Reindl, I've understood what happens with the automated entry of port 631 for udp/tcp and how to rewrite to not make it a world access (in/out) rule. Waiting for next install of F16 to test when and how the automated entry happens. I saw this entry in iptable