Re: [iptables] drop or accept policy for outgoing connections.

Daniel Curtis <[email protected]> Sat, 22 Jun 2013 20:40:48 +0200
Newsgroups gmane.linux.debian.devel.firewall
Message-ID <CAASvXNu+R8wMOXcsRhXxrHhxRj7E0crMdnQGRBVxkD4hB4A_iA@mail.gmail.com>
Hi, David. Thank you for correcting a rule for OUTPUT chain.
I mean that I forgot to add ... -P OUTPUT ... policy. I have only
one network device - router. Is that what you mean by writing
*network devices*?
So, according to your opinion, I have to use the second rule, right?
(iptables -P OUTPUT ACCEPT). I'm using the only one interface - eth0.

Pascal, what is the criterion, to optimize? Frankly, I don't know,
because it is a typical desktop. So, I think it does not need some
special criteria, right? Or maybe I'm wrong. What would you do
in my place? (so stupid question, sorry).

Best regards.