IPtables RAW vs FILTER
January 24, 2024•1,572 words
In discussions with a friend recently a question came up about the best place in netfilter / legacy iptables to filter out spurious traffic to the local addresses on a router. To be specific the use case is a Linux device acting as a router, with certain services running locally on it we want to use iptables to prevent customers connecting to (BGP, SSH, SNMP or whatever).
Question
My friend maintained it was always preferable to have the rules to drop such traffic in the the prerouting chain ...
Read post