4 ms·
The risk reduction is negligible if someone is doing a portscan on your host. Connection attempts to non standard ports will eventually occur. The better soluti
by sespindola 15y ago
The risk reduction is negligible if someone is doing a
portscan on your host. Connection attempts to non standard
ports will eventually occur.
The better solution is to use single packet
authorization.[1]
1. http://cipherdyne.org/fwknop/ http://cipherdyne.org/fwknop/
- Florin_Andrei 15y agoYeah. It depends on how persistent they are. Using DROP on all closed ports may discourage some attackers. Others may remain undeterred.