kvic said: ↑
it's more efficient to use "filter" rather than "raw" tables
Adamm said: ↑
Blocking a packet in raw means not only are there 4 less layers of processing by the kernel, but there's no overhead of conntracking.
We use essential cookies to make this site work, and optional cookies to enhance your experience.