Re: [fw-wiz] Traceroute

From: Paul Robertson (proberts_at_patriot.net)
Date: 10/21/03

  • Next message: Stephen D. B. Wolthusen: "[fw-wiz] Final call for full papers: IWIA 2004"
    To: Jim McAtee <jmcatee@mediaodyssey.com>
    Date: Mon, 20 Oct 2003 18:39:48 -0400 (EDT)
    
    

    On Sat, 18 Oct 2003, Jim McAtee wrote:

    > Is it generally considered safe to permit incoming UDP ports 33434+ through the
    > firewall to enable traceroute to reach destination machines? Or should it be
    > limited to a finite range of ports, or not permitted at all?

    I wouldn't permit it at all, UDP is too easy to spoof. In the past, I've
    had luck with setting up a traceroute CGI externally for users who just
    *had* to have the functionality. Reporting usage on that script got us
    quickly past the next request ;)

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    proberts@patriot.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Stephen D. B. Wolthusen: "[fw-wiz] Final call for full papers: IWIA 2004"

    Relevant Pages

    • Re: [fw-wiz] Traceroute
      ... > Is it generally considered safe to permit incoming UDP ports 33434+ ... > through the firewall to enable traceroute to reach destination machines? ... If you're not going to permit it, my recommendation would be to reject the ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Question about setting up PIX firewall
      ... > I would strongly disagree Paul. ... firewall there ... > amount of access while the user is connected to the vpn. ... But if you could find a client *and* compromise it, ...
      (Firewall-Wizards)
    • Re: Firewall trouble
      ... 90 permit icmp any host xxx.xxx.xxx.89 echo-reply ... ip inspect name firewall pop3 ... ip access-group ACL.permit.outbound ...
      (comp.dcom.sys.cisco)
    • Re: how to share internet connection in fedora
      ... Dear Paul, the first answer stile "if you don´t really tell us WHAT you need, we cannot provide you any kind of solution" was and is perfectly acceptable. ... > there is a basic firewall configuration utility in the distro. ... >> can u plz explain me how to share internet connection in fedora os ... > the machinations of the wicked." ...
      (Fedora)
    • Re: Microsoft has just released a public beta of Microsoft ActiveSync 4.2
      ... Paul T. ... I've got a Windows Mobile 2003 device sitting on the ... same PC that works perfectly and yet the new architecture which uses ... disabling of firewall settings or disabling the firewall. ...
      (microsoft.public.pocketpc.activesync)