From 272183207b6d5abbb9505dbd724a5a8aa5c794fa Mon Sep 17 00:00:00 2001 From: "/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=laforge/emailAddress=laforge@netfilter.org" Date: Mon, 30 Jan 2006 08:50:09 +0000 Subject: major manpage update (Yasuyuki Kozakai) --- extensions/libip6t_REJECT.man | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'extensions/libip6t_REJECT.man') diff --git a/extensions/libip6t_REJECT.man b/extensions/libip6t_REJECT.man index 75930f1..909d826 100644 --- a/extensions/libip6t_REJECT.man +++ b/extensions/libip6t_REJECT.man @@ -23,7 +23,7 @@ The type given can be .B " icmp6-port-unreachable" .B " port-unreach" .fi -which return the appropriate IPv6-ICMP error message (\fBport-unreach\fP is +which return the appropriate ICMPv6 error message (\fBport-unreach\fP is the default). Finally, the option .B tcp-reset can be used on rules which only match the TCP protocol: this causes a @@ -31,4 +31,6 @@ TCP RST packet to be sent back. This is mainly useful for blocking .I ident (113/tcp) probes which frequently occur when sending mail to broken mail hosts (which won't accept your mail otherwise). +.B tcp-reset +can only be used with kernel versions 2.6.14 or latter. -- cgit v1.2.3