Re: Proper Way to Pass ICMP Through Firewall-1?
From: Wolfgang Zweimueller (wzwei_at_gmx.at)
Date: 04/29/05
- Next message: Jason Edwards: "Re: is Zone allam locking up?"
- Previous message: MikeS: "Re: is Zone allam locking up?"
- In reply to: Will: "Re: Proper Way to Pass ICMP Through Firewall-1?"
- Next in thread: Will: "Re: Proper Way to Pass ICMP Through Firewall-1?"
- Reply: Will: "Re: Proper Way to Pass ICMP Through Firewall-1?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 29 Apr 2005 08:58:21 +0200
"Will" <DELETE_westes@earthbroadcast.com> writes:
> It ended up being a routing problem on the target device.
>
> And I *did* need to have two symmetric rules on the firewall, authorizing
> the transit of ICMP packets in both directions. For whatever reason, the
> firewall was not maintaining stateful inspection of ICMP, unlike other
> protocols.
Because there is no such thing like stateful filtering of ICMP. Well
there are some cases where you can think of stateful handling
(echo-request and echo-reply) but not in general. And if you want to
filter ICMP correctly you have to have knowledge about ICMP.
<flame mode>
ICMP is a major problem in most firewall appliances nowadays. E.g. the
Linksys WRT-boxes are very nice (and cheap), but you are unable to
handle ICMP properly. For me that is the main reason to remove the
Linksys firmware and install Openwrt.
I have seen so many bad or useless packet filters that makes me
believe that none of the implementors knows nothing about ICMP. That's
a nightmare.
</flame mode>
OTOH, Check Point is an exception and the way they allow you to handle
ICMP is O.K. for me.
cu,
Wolfgang
- Next message: Jason Edwards: "Re: is Zone allam locking up?"
- Previous message: MikeS: "Re: is Zone allam locking up?"
- In reply to: Will: "Re: Proper Way to Pass ICMP Through Firewall-1?"
- Next in thread: Will: "Re: Proper Way to Pass ICMP Through Firewall-1?"
- Reply: Will: "Re: Proper Way to Pass ICMP Through Firewall-1?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|