stason.org logo lotus


previous page: 16 I can't get .rhosts/.shosts to work with ssh.page up: comp.security.unix and comp.security.misc FAQnext page: 18 How do I prevent my machine from announcing OS version, daemon version, etc in the banner message?

17 Should I block all ICMP at my firewall/router?

 Books
 TULARC
















Description

This article is from the comp.security.unix and comp.security.misc FAQ, by Alan J Rosenthal flaps@dgp.toronto.edu with numerous contributions by others.

17 Should I block all ICMP at my firewall/router?

No. You need to allow the "can't fragment" message through or you will lose
connectivity to some number of sites with wacky packet sizes on their local
nets (notably token ring). See http://www.worldgate.com/~marcs/mtu/

Less crucially but still somewhat important, if you block the "destination
unreachable" message then you'll get timeouts, after a long wait, in some
cases when you could have received immediate "no route to host" messages.

But blocking some of the rest might not be a bad idea, especially "redirect".

 

Continue to:


Share and Enjoy

Bookmark this story so others can enjoy it:
  • digg
  • Reddit
  • del.icio.us
  • Furl
  • Wists

Tags

security, unix







TOP
previous page: 16 I can't get .rhosts/.shosts to work with ssh.page up: comp.security.unix and comp.security.misc FAQnext page: 18 How do I prevent my machine from announcing OS version, daemon version, etc in the banner message?