How to do: iptables drop fragments?

Viewed 1570

Describe: I try testing iptables block bad packages.

# Drop Various Attacks
iptables -A INPUT -p tcp --tcp-flags FIN,SYN FIN,SYN -j DROP
iptables -A INPUT -p tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN -j DROP
iptables -A INPUT -p tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j DROP
iptables -A INPUT -p tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
iptables -A INPUT -p tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j DROP
...
# Drop Fragments
iptables -A INPUT -f -j DROP

Find rule drop fragments no effective.

Test step: windows 10: 192.168.0.2 Linux(ubuntu 16.04): 192.168.0.5

Case 1:windows ping linux with option -l

ping 192.168.0.5 -l 3000 #icmp buffer size 3000
Result: ping OK.

Case 2:linux enable drop fragments

Linux:
iptables -A INPUT -f -j DROP
win10:
ping 192.168.0.5 -l 3000
Result: ping OK.

Find some info about iptables -A INPUT -f: Dropping IP fragments is probably obsolete advice: the Linux kernel can and will automatically re-assemble and sanity-check all fragments as needed anyway. This happens before packets are handled by iptables connection tracking, so it is likely this rule may never match anything.

Overall, it seems to me that you're either gathering up various firewall rules without completely understanding what they mean, or following outdated or incomplete advice.

My question: How to use iptable drop fragment packages?

0 Answers
Related