Re: About ping request?

From: Andrew Bailey (andrew.bailey@signatureflight.com)
Date: 05/19/02


Date: 19 May 2002 21:09:32 -0000
From: Andrew Bailey <andrew.bailey@signatureflight.com>
To: focus-ms@securityfocus.com


('binary' encoding is not supported, stored as-is) In-Reply-To: <Pine.LNX.4.44.0205172131100.25357-100000@lodos.ieee.metu.edu.tr>

Create a Packet filter rule on your firewall allowing ICMP
from internal network to extenal network.

Create a second Packet Filter rule on your firewall
denying ICMP from the external network to internal network.

That should give you the fexlibilty to ping outside your
network while denying anyone from outside your network to
ping any of your internal network.



Relevant Pages

  • Re: Firewall and DMZ topology
    ... > network, Windows and Linux. ... > laptop used as a simple firewall setup. ... > machine and placing it in a DMZ. ... > internal network, one for the DMZ and one for the Internet. ...
    (Security-Basics)
  • Re: outlook express, ipx and ftp :)
    ... I do the same type of thing with an OpenBSD firewall. ... >>From deny to allow in order for the internal network to be able to acess ... > $fwcmd add allow all from any to any via lo0 ...
    (FreeBSD-Security)
  • Re: Difficulties in Network Mapping & port scanning
    ... Chapter 11 (Firewalls) of Hacking Exposed Network Security Secrets and Solutions is also worth a read as it touches on enumeration through a Firewall. ... Also a very interesting few paragraphs on using non-echo ICMP messages for host enumeration. ... Subject: Difficulties in Network Mapping & port scanning Date: Tue, ...
    (Pen-Test)
  • RE: Firewall and DMZ topology
    ... which is on the internal network. ... You should ask yourself why you need a firewall with a DMZ port. ...
    (Security-Basics)
  • Loopback Address Spoofing? 2nd Posting - Modified.
    ... I am a frequent reader of this list and contribute when ... This investigation came about because the firewall my friend uses is ... and had been moved to the internal network recently. ...
    (Security-Basics)