RE: disable traceroute to my host

From: Enriko Groen (enriko.groen@netivity.nl)
Date: 06/25/01


From: Enriko Groen <enriko.groen@netivity.nl>
To: 'alexus' <ml@db.nexgen.com>, freebsd-security@FreeBSD.ORG, freebsd-isp@freebsd.org
Date: Mon, 25 Jun 2001 09:00:18 +0200


> -----Original Message-----
> From: alexus [mailto:ml@db.nexgen.com]
>
> is it possible to disable using ipfw so people won't be able
> to traceroute
> me?

You could with IPfilter which has a fastroute option which will not lower
the hopcount.
However I think this will only work if you use this feature on a firewall.

--
Enriko Groen, Hosting manager
--------------------------------------------------------
netivity bv   www.netivity.nl   enriko.groen@netivity.nl
038 - 850 1000   van nagellstraat 4      8011 eb  zwolle
--------------------------------------------------------
 
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: FTP problem with IPFW
    ... Please do send the sample ipfilter rules. ... To give you an idea about my requirements, my complete IPFW ... Firewall with IPFILTER" ... > All seems to be working fine, except for FTP. ...
    (freebsd-questions)
  • RE: What exactly is ipfilter?
    ... FBSD comes with two firewall applications built into the base ... IPFW and IPFILTER. ...
    (freebsd-questions)
  • Re: /etc/rc.firewall fixes
    ... > I would like to see configuration code for ipfw AND ipfilter ... ipf got its hooks before 4.2-RELEASE. ... never make it into ipfilter itself. ... This enables you to do some rc.firewall like things ...
    (FreeBSD-Security)
  • Re: routing problem
    ... seem to like it a lot - and I use ipfw because I know how to. ... The ipfilter was nating, but I'm not sure about the NAT rules inside the ... temporary firewall rules to log everything in and out per interface .. ... it to static and cloned routing, but taking it out of the mix might help ...
    (freebsd-questions)
  • Re: IPFW, IPFilter and NAT
    ... >> ipfilter and dummynet I don't know. ... > compile them in kernel, then the answer was not stated. ... a second check does the same for IPFW. ... also allow me to use IPFW stateful features on NAT'ed connections, ...
    (comp.unix.bsd.freebsd.misc)