Re: [fw-wiz] Traceroute

From: Michael C. Toren (mct_at_toren.net)
Date: 10/21/03

  • Next message: Christopher L. Everett: "Re: [fw-wiz] Recommendation needed for a firewall appliance"
    To: Jim McAtee <jmcatee@mediaodyssey.com>
    Date: Mon, 20 Oct 2003 23:01:41 -0400
    
    

    On Sat, Oct 18, 2003 at 04:51:56PM -0600, Jim McAtee wrote:
    > Is it generally considered safe to permit incoming UDP ports 33434+
    > through the firewall to enable traceroute to reach destination machines?
    > Or should it be limited to a finite range of ports, or not permitted at
    > all?

    If you're not going to permit it, my recommendation would be to reject the
    inbound packets with an ICMP port-unreachable response rather than simply
    dropping them on the floor. This way, at least a traceroute will terminate
    cleanly as opposed to timing out.

    -mct
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Christopher L. Everett: "Re: [fw-wiz] Recommendation needed for a firewall appliance"

    Relevant Pages

    • Re: [fw-wiz] Traceroute
      ... > firewall to enable traceroute to reach destination machines? ... I wouldn't permit it at all, UDP is too easy to spoof. ... Paul D. Robertson "My statements in this message are personal opinions ...
      (Firewall-Wizards)
    • Re: Firewall trouble
      ... 90 permit icmp any host xxx.xxx.xxx.89 echo-reply ... ip inspect name firewall pop3 ... ip access-group ACL.permit.outbound ...
      (comp.dcom.sys.cisco)
    • Re: Win XP ICF - permit all traffic from one IP address?
      ... The firewall doesnt affect IPX traffic, ... > and connect directly to the Internet via a DSL ... > Now I would really like to have Internet Connection ... > way to add the equivalent of a "PERMIT ALL FROM IP ...
      (microsoft.public.security)
    • Re: Problem with Windows XP, Norton Internet Security 2007 or Word
      ... Open NIS, go to the FIREWALL. ... Click on the PROGRAMS tab & give WINWORD.EXE ... 'Permit Always' access. ... Then, download and install Avast! ...
      (microsoft.public.windowsxp.general)
    • Re: NOrton and Pokerstars
      ... > Allowd pokerstars at base level -- didn't help. ... > my windows firewall is still on. ... remove PokerStarsUpdate.EXE from the list of authorized "Permit All" ... Norton will ...
      (rec.gambling.poker)