Re: FW-1 gateway sends ICMP packets

From: lolofe (lolofe@email.com)
Date: 05/30/02


From: lolofe@email.com (lolofe)
Date: 30 May 2002 06:30:18 -0700

eirik@mi.uib.no (Eirik Seim) wrote in message news:<slrnafasbd.5nl.eirik@kain.mi.uib.no>...

> > So my question is : how can I prevent the firewall gateway from
> > sending such an ICMP packet to the originating host ? Is it related to
> > point 1-) ?
>
> Yes, it does sound like its related. I understand perfectly why you
> dont want to _pass_ all ICMP traffic, but why dont you want your
> firewall to send time-exceeded? Any real reason, or does it simply
> seem to be a Good Thing?

In its current configuration, the firewall can't be pinged.
It will also stop traceroutes to the destination, so it can't be
detected this way.
And its open ports are not visible from the Internet.

So, the firewall gateway is nearly "invisible" from the internet, but
these 'ICMP TTL exceeded' packets permit to detect its presence (and
its IP address).



Relevant Pages

  • Re: Help - Tried almost everything!
    ... still have no answer why the ICMP still goes out every ... >> a periodic router advertisement. ... >>>|>>installed the Firewall after I suspected a problem ... but this is just an ICMP packet that's ...
    (microsoft.public.security)
  • Re: Help - Tried almost everything!
    ... I looked it up in the firewall codes and it is a ... >>Then it is probably ICMP type 10 Router Solicitation: ... but this is just an ICMP packet that's sent ...
    (microsoft.public.security)
  • RE: [fw-wiz] [fw-wiz]: unable to ping internet servers
    ... You have to allow inbound ICMP echo-reply packets. ... of the same sequence of events as the earlier outgoing echo-request. ... we are accessing the internet having direct connection from the firewall ...
    (Firewall-Wizards)
  • Re: FW-1 gateway sends ICMP packets
    ... >> sending such an ICMP packet to the originating host? ... the firewall can't be pinged. ... And its open ports are not visible from the Internet. ...
    (comp.security.firewalls)
  • Re: GRC and Cisco PIX 501
    ... Ping Reply: RECEIVED - Your system REPLIED to our Ping (ICMP ... making it visible on the Internet. ... Hiding ICMP is a very weak and obscure countermeasure. ... So if you think you'll need to hide your firewall from the internet better ...
    (comp.dcom.sys.cisco)

Quantcast