Re: PIX firewall and ICMP

From: Brian Ford (brford_at_cisco.com)
Date: 09/26/03

  • Next message: Shaolin Tiger: "Re: book recommendations"
    Date: Fri, 26 Sep 2003 16:20:01 -0400
    To: "Cat Thrasher" <isd607@co.santa-cruz.ca.us>
    
    

    Cat,

    I hope you recognize that the "any any" was a big mistake.

    This is an excellent example of the trade offs of implementing a security
    solution. You need to weigh the worm clean up costs against the decision
    to allow users to use ping for troubleshooting.

    Liberty for All,

    Brian

    At 10:21 AM 9/24/2003 -0700, Cat Thrasher wrote:
    >Please advise your opinions on my problem. I had a permit statement on the
    >PIX that would allow ICMP from any to any. Since being hit with Nachi, I
    >turned it off. I am being asked my policy on when it will be turned back
    >on. I have a rather large network and many "divisions" who work
    >independently, yet access the internet thru "my" PIX. They like to use
    >ping when trouble-shooting.
    >Can I get an opinion on whether or not I should turn this back on...
    >Thanks
    >
    >Cat Thrasher
    >Network Support Analyst
    >County of Santa Cruz
    >831-454-5367
    >cat.thrasher@co.santa-cruz.ca.us
    >
    >
    >---------------------------------------------------------------------------
    >----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Shaolin Tiger: "Re: book recommendations"

    Relevant Pages

    • RE: PIX firewall and ICMP
      ... I agree with Brian. ... to allow users to use ping for troubleshooting. ... >Please advise your opinions on my problem. ...
      (Security-Basics)
    • Re: 98/2000/xp network
      ... can you ping it bu name? ... Posting on MS newsgroup will benefit all readers and you may get more help. ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ... Help small network with 98/2000/xp machines. ...
      (microsoft.public.win2000.networking)
    • Re: cannot ping and access from some pc in workgroup
      ... troubleshooting ping issuesIf you can't ping outside IP, make sure you have correct gateway. ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ...
      (microsoft.public.windowsxp.network_web)
    • Re: Pinging 192.168.1.x IP address returns wrong IP
      ... this is DNS suffix issue. ... troubleshooting ping issuesPing lists a public IP instead of private IP. ... Networking, Internet, Routing, VPN Troubleshooting on ...
      (microsoft.public.windowsxp.network_web)
    • Re: Ok to let all ICMP traffic through firewall?
      ... > need to allow PING, in fact why the heck would you want to allow PING, ... *I* certainly can - usually when the web server has had a bit of a ... and one needs to tell if it's the server behind the firewall ... the opinions expressed in this opinion do not necessarily ...
      (comp.security.misc)