blob: c419a85e48219ab3baaf6ededc9cb84501ed7c23 [file] [log] [blame]
Henrik Nordstromc2794132004-01-22 15:04:24 +00001This is used to send back an error packet in response to the matched
2packet: otherwise it is equivalent to
3.B DROP
4so it is a terminating TARGET, ending rule traversal.
5This target is only valid in the
6.BR INPUT ,
7.B FORWARD
8and
9.B OUTPUT
10chains, and user-defined chains which are only called from those
11chains. The following option controls the nature of the error packet
12returned:
13.TP
Jan Engelhardtfea74bf2009-01-12 04:53:18 +010014\fB\-\-reject\-with\fP \fItype\fP
Henrik Nordstromc2794132004-01-22 15:04:24 +000015The type given can be
Jan Engelhardtfea74bf2009-01-12 04:53:18 +010016\fBicmp\-net\-unreachable\fP,
17\fBicmp\-host\-unreachable\fP,
18\fBicmp\-port\-unreachable\fP,
19\fBicmp\-proto\-unreachable\fP,
20\fBicmp\-net\-prohibited\fP,
21\fBicmp\-host\-prohibited\fP or
22\fBicmp\-admin\-prohibited\fP (*)
23which return the appropriate ICMP error message (\fBport\-unreachable\fP is
Henrik Nordstromc2794132004-01-22 15:04:24 +000024the default). The option
Jan Engelhardtfea74bf2009-01-12 04:53:18 +010025\fBtcp\-reset\fP
Henrik Nordstromc2794132004-01-22 15:04:24 +000026can be used on rules which only match the TCP protocol: this causes a
27TCP RST packet to be sent back. This is mainly useful for blocking
28.I ident
29(113/tcp) probes which frequently occur when sending mail to broken mail
30hosts (which won't accept your mail otherwise).
Jan Engelhardtaeafdb82008-08-12 11:42:04 +020031.PP
Jan Engelhardtfea74bf2009-01-12 04:53:18 +010032(*) Using icmp\-admin\-prohibited with kernels that do not support it will result in a plain DROP instead of REJECT