Re: Kerio 2.1.5 Vulnerability

From: Alan Illeman (illemann_at_surfbest.net)
Date: 05/31/04


Date: Sun, 30 May 2004 19:06:07 -0400


"Stalks" <sorry@dont.want.spam.tv> wrote in message
news:Penuc.5601328$iA2.650745@news.easynews.com...
> Alan Illeman wrote:
>
> (snip)
>
> > If I block outgoing Echo Reply [0], by ISP closes down my (dialup)
> > connection.
> >
>
> Little OT:
>
> Try enabling a specific rule to allow all ICMP, but log packets. Look at
the log to see where the
> ICMP Echo Requests are originating from and then add another rule to allow
ICMP Requests only from
> that origin, then "deny all icmp" afterwards, this would increase the
stealth of your firewall
> somewhat but not have your ISP disconnect you for apparent inactivity.

I thought of that, but the server address varies.