Using "ipchains -P forward DENY" instead of disabling ip-forwarding?

Post by Peter Eisenloh » Thu, 22 Jul 1999 04:00:00

Hi all,

ist there any difference (as seen from the outside) between
a) a host with ip_forwarding disabled and
b) a host with ip_forwarding enabled, but blocking all packets with
   the default-rule of the forwarding-chain set to DENY?

I have not been able to find a real FTP-Proxy for Linux. There is one
with the TIS firewall toolkit, which is not applicable for us. So it was
idea to use Linux' Masquerading functionality to do the ftp "proxying".
(caching is not required). Are there any major security drawbacks with

thanx for any hints,


