Iptables --reject-with tcp-reset for non-TCP traffic
10 Mar 2021, 12:46 UTC
Here I faced with a bit strange rule:
iptables -A INPUT -s 10.26.95.20 -j REJECT --reject-with tcp-reset
This rule matches all the protocols from specific network and rejects it with TCP RST packet.
How is this supposed to work with non-TCP packets? If other end (10.26.95.20) sends UDP packet it then receives TCP RST? This looks extremely strange..
1 answer
Accepted answer · original discussion
12 Mar 2021, 12:46 UTC
Yeah, it makes no sense. IPTABLES also errors when I attempt to issue this on the command line (tested on CentoOS 8). It can only work if -p tcp is given which specifies that the rule is dealing with TCP traffic. Then it will work.
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
14 Mar 2021, 12:46 UTC