Re: disable traceroute to my host

From: Brooks Davis (
Date: 06/23/01

Date: Fri, 22 Jun 2001 16:04:43 -0700
From: Brooks Davis <>
To: alexus <>

On Fri, Jun 22, 2001 at 06:32:10PM -0400, alexus wrote:
> is it possible to disable using ipfw so people won't be able to traceroute
> me?

Not really. Traceroute works be setting the hop count of an IP packet
very low so that it gets an ICMP error message back from each router along
the way. You might be able to set things up to hide your internal network
by not changing the hop count when packets pass through your routers,
but that's it. You can do this with FreeBSD, but I can't seem to find
the option at the moment.

-- Brooks

Any statement of the form "X is the one, true Y" is FALSE.
PGP fingerprint 655D 519C 26A7 82E7 2529  9BF0 5D8E 8BE9 F238 1AD4

To Unsubscribe: send mail to
with "unsubscribe freebsd-security" in the body of the message

Relevant Pages

  • Re: Slow Internet connection for Fedora 4
    ... $ traceroute ... followed by how long it takes a packet to get ... over hop 5 when traceroute's looking at hop 13, ... Some routers don't support this. ...
  • Re: Nmap Causes DNS Issue
    ... >NAT enabled on my router, ... the intent was to use the -p option to cause traceroute to try to ... That suggests it's something on the next hop or two. ... to port 53 - trying each step along the way to the name servers). ...
  • Re: Connection problem
    ... PING fails and TRACEROUTE gets to the last hop before the site. ... Have you tried changing MTU settings on router and/or PC? ...
  • Re: tcp_mtu_discover causes traceroute problems on aix 4.3.3
    ... > (because the traceroute fails). ... However, a severe misunderstanding is, that "Path MTU Discovery" ... Let's have a look on how PMTU discovery works. ... If a router is well behaved, i.e. it politefully obeys all the ...
  • Re: Strange web site loading/DNS problem
    ... If the site sends out packets of 1500 bytes, and there is a router between ... When I can't get to the site, I get the typical traceroute: ... I have also changed the DNS server info in my router, ...