Firewalld drop zone?

Beautiful good day,

I'm currently experimenting with Firewalld and am a bit confused.

According to the description: "drop

Any incoming network packets are dropped, there is no reply. Only outgoing network connections are possible."

Now if I add my interface to the drop zone, I still get responses to my requests (e.g. apt download nginx).

Does the description mean that every unexpected packet is dropped or really every one and I have misconfigured something?

thanks in advance : )

(1 votes)

Similar Posts

Notify of
1 Answer
Newest Most Voted
Inline Feedbacks
View all comments
5 months ago

Starting traffic and packages that come back and belong to this session will not be dropped.

If someone from the internet attempts to initiate a blurry to your systems, these will be dropped

That only your systems can initiate a session from inside to outside.

This is called stateful firewall.