Re[3]: icmp problem

From: BigBrother-{BigB3} (bigbrother_at_bonbon.net)
Date: 05/13/05

  • Next message: Garrett Wollman: "Re: FreeBSD Security Advisory FreeBSD-SA-05:09.htt [REVISED]"
    Date: Fri, 13 May 2005 19:43:21 +0300 (EEST)
    
    

    On Fri, 13 May 2005, Danil V. Gerun wrote:

    > BB> In my NATED (ipfw+natd) lan EVERY internal host (192.168.XX) can ping
    > BB> simultaneously any external host and ALL getting their proper ICMP
    > BB> replies.
    >
    > Well, I didn't configure "ICMP NAT" for my LAN, but I'm just
    > wondering: what if _some_ internal hosts start pinging one external
    > host? Is each of them going to recieve all the icmp replies?..
    >
    >
    >

    As I told you If _some_ internal hosts start pinging one external host,
    everyone gets their proper answer. They are not going to receive all the
    icmp replies. Everyone receives his reply. Use

    natd -v

    to figure out

    Here is a snip:

    Out [ICMP] [ICMP] 192.168.???.130 -> 192.108.???.43 8(0) aliased to
                [ICMP] 193.92.???.26 -> 192.108.???.43 8(0)
    In [ICMP] [ICMP] 192.108.???.43 -> 193.92.???.26 0(0) aliased to
                [ICMP] 192.108.???.43 -> 192.168.???.130 0(0)

    Make some experiments with

    natd -v

    and you will understand this.

    ---
    Dreams have no limits!
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Garrett Wollman: "Re: FreeBSD Security Advisory FreeBSD-SA-05:09.htt [REVISED]"

    Relevant Pages

    • Re[3]: icmp problem
      ... BB> In my NATED lan EVERY internal host can ping ... BB> simultaneously any external host and ALL getting their proper ICMP ... Is each of them going to recieve all the icmp replies?.. ...
      (FreeBSD-Security)
    • Re: How do I stop my PC from returning a "Ping"?
      ... to send out packets and retrieve the incoming replies as well. ... I would bet that he is behind a router, the router is getting the IP ... The router probably can be set up to disable ICMP ... >> Hmmm, but "ping of death" attacks could be pretty major, should they ...
      (microsoft.public.windowsxp.security_admin)