MAESTRO WIRELESS SOLUTIONS
| Network
178
E SERIES | USER MANUAL VERSION 2.2.0
http://support.maestro-wireless.com
Drop vs Reject
DROP
less information is exposed
less attack surface
client software may not cope well with it (hangs until connection times
out)
may complicate network debugging (where was traffic dropped and why)
REJECT
may expose information (like the ip at which traffic was actually blocked)
client software can recover faster from rejected connection attempts
network debugging easier (routing and firewall issues clearly
distinguishable)