From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id 7DB151382C5 for ; Sat, 5 Jan 2013 01:31:43 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 5F9D121C019; Sat, 5 Jan 2013 01:31:30 +0000 (UTC) Received: from ironport2-out.teksavvy.com (ironport2-out.teksavvy.com [206.248.154.182]) by pigeon.gentoo.org (Postfix) with ESMTP id 00A1921C004 for ; Sat, 5 Jan 2013 01:30:08 +0000 (UTC) X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: Aq8NAG6Zu09FxKsZ/2dsb2JhbABEgXuwewOBGIEIghUBAQU6HDMLGAkTEg8FJTeIDgu5fotigUSCPGIDiEKEfIIZhUOFX4g6gViDBw X-IronPort-AV: E=Sophos;i="4.75,637,1330923600"; d="scan'208";a="211434399" Received: from 69-196-171-25.dsl.teksavvy.com (HELO waltdnes.org) ([69.196.171.25]) by ironport2-out.teksavvy.com with SMTP; 04 Jan 2013 20:30:07 -0500 Received: by waltdnes.org (sSMTP sendmail emulation); Fri, 04 Jan 2013 20:29:49 -0500 From: "Walter Dnes" Date: Fri, 4 Jan 2013 20:29:49 -0500 To: gentoo-user@lists.gentoo.org Subject: Re: [gentoo-user] IPTABLES syntax change? Message-ID: <20130105012949.GA17261@waltdnes.org> References: <50DBA7D0.4060800@orlitzky.com> <87zk0zivjk.fsf@einstein.gmurray.org.uk> <20121227231150.GA9864@waltdnes.org> <50DCDEAF.9020002@orlitzky.com> <20121228035937.GA2949@waltdnes.org> <50DD370F.4070509@orlitzky.com> <20121231032150.GA2032@waltdnes.org> <50E509FA.3060204@orlitzky.com> <20130104201702.GA16813@waltdnes.org> Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-user@lists.gentoo.org Reply-to: gentoo-user@lists.gentoo.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.21 (2010-09-15) X-Archives-Salt: abda12cb-f396-4e3a-b8a3-024553e2bc49 X-Archives-Hash: 82af432970d91c39c19b37aba5f4724c On Fri, Jan 04, 2013 at 03:27:59PM -0500, Michael Mol wrote > On Fri, Jan 4, 2013 at 3:17 PM, Walter Dnes wrote: > > > > The mere fact that you haven't manually typed in... > > http://www.facebook.com/blah_blah_blah does not mean you're not > > connecting to it. > > But all that's above layer 3, since it's an HTTP redirect, or a page > transclusion which necessitates a new GET request. Michael's point > stands. And I want to make sure that new GET request is blocked coming and going. -- Walter Dnes I don't run "desktop environments"; I run useful applications