Re: Best way to filter "Nachi pings"?

From: Andy Farkas (andyf_at_speednet.com.au)
Date: 10/30/03

  • Next message: Pete Ehlke: "Re: /var partition overflow (due to spyware?) in FreeBSD default install"
    Date: Thu, 30 Oct 2003 13:01:37 +1000 (EST)
    To: Jarkko Santala <jake@iki.fi>
    
    

    On Mon, 27 Oct 2003, Jarkko Santala wrote:
    > On Mon, 27 Oct 2003, Kris Kennaway wrote:
    > > On Mon, Oct 27, 2003 at 11:06:52AM +0200, Jarkko Santala wrote:
    > > >
    > > > Definitely this block-all approach is not sane, its like if someone
    > > > complains about NFS being broken you'd say disable it. Filtering packets
    > > > by length on the other hand is a very nice feature to have.
    > >
    > > As it happens, ipfw[2] does this anyway.
    >
    > IMHO this is the correct answer that might have been given right away.

    So, using IPFW2, a rule to block the nachi ping would look like:

      add deny icmp from any to any in icmptypes 8 iplen 92

    correct?

    --
     :{ andyf@speednet.com.au
            Andy Farkas
        System Administrator
       Speednet Communications
     http://www.speednet.com.au/
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Pete Ehlke: "Re: /var partition overflow (due to spyware?) in FreeBSD default install"

    Relevant Pages

    • RE: Bridging and IPFW
      ... No impact whatsoever! ... >>According to what I have read, using ipfw2 I should now be able to ... >>properly filter by MAC address..so I wrote up some rules! ... To unsubscribe, ...
      (freebsd-questions)
    • Re: address specified as 1.2.3.4/24{128,35-55,89} Is this Correct ????
      ... Do you use ipfw2? ... It's not default on FreeBSD 4.x systems. ... And maybe you should quote ... To unsubscribe, ...
      (FreeBSD-Security)
    • Denying Multiple login in samba with ipfw2
      ... Can i deny multiple login with the same username in samba using ipfw2? ... RdBSD ... IT Staff ... To unsubscribe, ...
      (freebsd-questions)
    • Re: unicast octets statistics
      ... ifInOctets counts broadcasts too. ... I finished with ipfw2, thank you all. ... Eugene ... To unsubscribe, ...
      (freebsd-net)
    • ipfw: pullup failed
      ... My router that uses ipfw2 for WF2Q+ sometimes writes in log: ... Eugene Grosbein ... To unsubscribe, ...
      (freebsd-net)