Re: Removing ping/icmp from a network



On Thu, Mar 27, 2008 at 12:25 PM, Jason <securitux@xxxxxxxxx> wrote:
*snip*
The idea is to limit your Internet footprint to make it as difficult
as possible for an attacker. There is no need for a web server to
respond to ping from the Internet for example.

It is very critical that your web server responds to ICMP on the
Internet. If you go out of the way and ignore essential protocols for
IP over a public network, you're just going to create a headache for
all of us.

Without ICMP, it is very difficult for us to determine where a problem
exists when our clients complain about slow load times or
inaccessibility to your website. No ICMP means no basic trace
routing, no basic latency checks, and no basic error reporting. So
even if the problem is somewhere in our infrastructure that limits or
prevents access to your site, you're going to get the blame and bad
reputation of an unstable server. If it doesn't respond to ping, and
can't be traced, its not our fault that our client can't access your
site, it's yours.

--
Mark Owen



Relevant Pages

  • RE: ICMP (Ping)
    ... You are correct about the kinder and gentler internet. ... network to deal with I might share your opinion. ... I believe you meant ICMP echo ... Subject: ICMP (Ping) ...
    (Security-Basics)
  • Re: Router Firewall Einstellungen
    ... > - does not respond to Ping on Internet Port ... Reaktion auf ICMP Typ 8? ... > verbindungsaufbauten aus deinem netz ins internet durchlassen wird. ... Wenn du UPnP aktivierst, kann sich jeder Eindringling bei deiner ...
    (de.comp.security.firewall)
  • Re: Removing ping/icmp from a network
    ... OrgName: Internet Assigned Numbers Authority ... > ICMP is allowed throughout most Internet routers, ... > manage the server of course). ... > if they can ping it or not if they can't access their data through SSL ...
    (Security-Basics)
  • RE: HPing?
    ... legitimate ICMP protocol used to check whether the destination host is ... lot more than a normal ICMP ping, it can do a TCP (with any artbitrary ... port 80 with a syn tcp/ip packet and see if the box has a web server. ... The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • Re: GRC and Cisco PIX 501
    ... Ping Reply: RECEIVED - Your system REPLIED to our Ping (ICMP ... making it visible on the Internet. ... Hiding ICMP is a very weak and obscure countermeasure. ... So if you think you'll need to hide your firewall from the internet better ...
    (comp.dcom.sys.cisco)