- The principle of least privilege.
- Block will drop traffic silently, while Reject will send back a packet (RST for TCP or ICMP Port Unreachable for UDP).
- We will be able to connect to Recode; the block rule will have no effect because it was placed after the "Allow LAN to any" rule.
- We will not be able to connect to Recode; the block rule will match the traffic to Recode before the “Allow LAN to any” rule.
- (a) We will not be able to connect to Recode; the new “default allow” rule will be invoked after the block rule. (b) We will be able to connect to Recode; the new "default allow" rule will be invoked before the block rule. (c) The default "Allow LAN to any" rules have no effect on traffic flow anymore ...