<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Nftables on Damien Dyes Blog</title>
    <link>https://blogs.damiendye.uk/de/tags/nftables/</link>
    <description>Recent content in Nftables on Damien Dyes Blog</description>
    <generator>Hugo</generator>
    <language>de-DE</language>
    <lastBuildDate>Tue, 01 Sep 2026 08:05:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/de/tags/nftables/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Ping: das Diagnosewerkzeug, das viel mehr öffnet</title>
      <link>https://blogs.damiendye.uk/de/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</link>
      <pubDate>Tue, 01 Sep 2026 08:05:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/de/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</guid>
      <description>Warum Ping — ICMP Echo, nicht das restliche Protokoll — ein Risiko ist: ein Kanal, den jeder Host beantworten muss, sodass ein Netz, das ‚nur Ping erlaubt‘, ein VPN nach draußen hat. Die Bedrohung, wer eines öffnet, drei Tunnel (Hans, icmptunnel, einer in Python mit AES-128) und die Regel dagegen: nftables, pf, Cisco, Junos, MikroTik.</description>
    </item>
  </channel>
</rss>
