RE: Best way to filter "Nachi pings"?

From: Colin Percival (colin.percival_at_wadham.ox.ac.uk)
Date: 10/27/03

  • Next message: Francis A. Vidal: "RE: Best way to filter "Nachi pings"?"
    Date: Mon, 27 Oct 2003 08:11:07 +0000
    To: "Francis A. Vidal" <francisv-dated-1067846809.52fc3d@irc.dagupan.com>, <freebsd-security@freebsd.org>
    
    

    At 16:06 27/10/2003 +0800, Francis A. Vidal wrote:
    >Wouldn't it break stuff like traceroute?

       Traceroute is fine -- it uses UDP packets. Tracert, on the other hand,
    uses ICMP echo request packets, and it suffers. I'm currently on a
    university network, and when there are connectivity issues (which seems to
    be quite often) I get very annoyed with the ICMP filtering.

    Colin Percival

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Francis A. Vidal: "RE: Best way to filter "Nachi pings"?"

    Relevant Pages

    • IpSec Woes.
      ... > REGISTER ... > ESP/Transport ... >in order to set the SA up: you'll see the first ICMP Echo Request ... subsequent ICMP Echo Request packets should ...
      (Fedora)
    • Re: ping fails; traceroute is OK
      ... `ping' sends ICMP echo request packets to the hosts and waits for an ... ICMP echo reply. ...
      (comp.os.linux.networking)