Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
dpcreconsiler: Restrict ICMP rule to echo-request only.
Previously, the iptables rule allowed all ICMP traffic to enter the device. This change restricts it to only allow ICMP echo-request packets, reducing exposure to unnecessary ICMP message types. Return ICMP traffic remains unaffected as it is already covered by the RELATED,ESTABLISHED rule in the INPUT chain. This improves security by limiting external ICMP access to only what is necessary. Signed-off-by: Alexandros Kaouris <[email protected]>
- Loading branch information