Re: Best way to filter "Nachi pings"?

From: David G. Andersen (danderse_at_cs.utah.edu)
Date: 10/27/03

  • Next message: Gaspar Chilingarov: "Re: Best way to filter "Nachi pings"?"
    Date: Mon, 27 Oct 2003 09:32:47 -0700
    To: Brett Glass <brett@lariat.org>
    
    

    Brett Glass just mooed:
    > At 03:17 AM 10/27/2003, Jarkko Santala wrote:
    >
    > >Blocking
    > >all ping packets to improve security is nothing more than security through
    > >obscurity. It may hide your system against the simplest ping probes, but
    > >it does nothing to improve security as such.
    >
    > In our case, there's a more compelling reason.
    >
    > Some of our customers' system administrators have utilities
    > which ping their servers from their home Internet connections
    > to make sure everything's working. If I were to block pings,
    > all of these guys' (and gals') pagers and cell phones would go
    > off at once. I'd be beseiged with demands to remove the block
    > immediately.

      Rate-limit them with dummynet on somewhat selective per-subnet
    basis. It's not perfect, and increases the latency perceived by
    customers running ping, but it helps a lot compared to doing
    nothing.

      -dave

    -- 
    work: dga@lcs.mit.edu                          me:  dga@pobox.com
          MIT Laboratory for Computer Science           http://www.angio.net/
          I do not accept unsolicited commercial email.  Do not spam me.
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Gaspar Chilingarov: "Re: Best way to filter "Nachi pings"?"

    Relevant Pages

    • Re: Removing ping/icmp from a network
      ... vendors / admins / whatever. ... A ping sweep isn't the only way to do network exploration. ... which won't gain you any security. ...
      (Security-Basics)
    • Re: WMI/COM and ExecNotificationQueryAsync for Win32_NTLogEvent
      ... because such computer excluded from the network the ping would fail. ... So it seems that I need to set up security ... thing or a WQL query issue, ... listener via ExecNotificationQueryAsync in a C++/COM environment, ...
      (microsoft.public.win32.programmer.networks)
    • Re: NTP, ntpdate, and ISP-based firewall
      ... >> barriers beyond the basic firewall. ... > Layered defenses are indeed the correct way to build up security. ... > mechanisms like ping, traceroute and tcpdump. ... > Put a firewall in front of your local network. ...
      (Fedora)
    • Re: Best way to filter "Nachi pings"?
      ... >all ping packets to improve security is nothing more than security through ... >obscurity. ... If I were to block pings, ...
      (FreeBSD-Security)
    • Re: Accessing file on PC over network
      ... Can you ping the RISCOS computer ... RPC, but not the other way round. ... But one of the security updates could have to tighten security, ...
      (comp.sys.acorn.networking)