All,
Can someone with an iptables router, running the dynamic filtering scripts (using IPSET OR IPTABLES) do the following.
- make an IP tables rule AFTER (-A [APPEND]) your ALLOW IPENCAP from AMPRGWS - to DROP IPENCAP - let us know if you get any firewall hits by checking your running ipencap list
I accepted IPENCAP without connection tracking for a long time, so i have no netfilter information, unless it was a Nested IPENCAP packet that was received at tunl0.
73,
- Lynwood KB3VWG