SurprisedItWorks DD-WRT Guru
Joined: 04 Aug 2018 Posts: 1447 Location: Appalachian mountains, USA
|
Posted: Mon Nov 26, 2018 17:28 Post subject: Observation: logreject in iptables only rejects tcp |
|
I use iptables commands to get network isolation between subnets, and it turns out that using either a logreject target or logdrop target will create a WEBDROP system-log entry, but only logdrop will actually stop a ping across subnet IP-space boundaries. Looking at the logreject and logdrop chains in iptables shows why: logdrop drops everything, while logreject drops only tcp connections.
It's been a while since I experimented with REJECT and DROP, but my recollection is that they worked correctly, on icmp "ping" tests as with everything else.
I call it a bug, but maybe that's just me. (And if it is, I have no idea how to create a bug report.) _________________ 2x Netgear XR500 and 3x Linksys WRT1900ACSv2 on 53544: VLANs, VAPs, NAS, station mode, OpenVPN client (AirVPN), wireguard server (AirVPN port forward) and clients (AzireVPN, AirVPN, private), 3 DNSCrypt providers via VPN. |
|