Re: Ok to let all ICMP traffic through firewall?

From: Walter Roberson (roberson_at_ibd.nrc-cnrc.gc.ca)
Date: 09/23/05


Date: Thu, 22 Sep 2005 23:06:03 +0000 (UTC)

In article <433331d9$0$32652$da0feed9@news.zen.co.uk>,
Peter <abuse@dopiaza.cabal.org.uk> wrote:
:However blocking all
:ICMP is throwing the baby out with the bathwater and will cause more
:bother than not blocking anything.

"more bother" depends on whether you are being deliberately attacked
or not.

:I would suggest allowing ICMP Echo and Echo Reply (so ping works),

Typically, outsiders have no business mapping out exactly which
of your systems exist or are up right now, so dropping most incoming icmp
echo is a common security precaution. Whether to allow icmp echo
to public-facing servers varies with circumstance.

-- 
  If you like, you can repeat the search with the omitted results included.


Relevant Pages

  • Re: 2000 server solution
    ... Definitely not on layer 2 or 3. ... Give me a reason to hide something, that is designed for public access. ... tcp-rst or icmp port unreachable is ... Yes, so please explain, why you consider ICMP echo replies und icmp echo ...
    (comp.security.firewalls)
  • Re: Domain nicht mehr erreichtbar
    ... Dieser Host antwortet nicht auf ICMP ECHO Requests. ... Verbindungsprobleme mit den GMX Servern einbrachte), ...
    (de.comp.sys.mac.internet)
  • Re: Stealthing
    ... is no authentication that an ICMP ECHO packet comes from the IP ... security gateways that respond with ICMP Unreachables, ... If the gateway just drops the ICMP ECHO packet without reply, ...
    (comp.security.misc)
  • Re: Sicherer Webserver?
    ... ICMP ECHO zu rejecten ... eher ICMP ECHO zu droppen (was die Sache zwar auch nicht wesentlich ... aber keine "Haluk'schen Schwarzlochfilter fuer ICMP". ...
    (de.comp.os.unix.linux.misc)
  • Re: Ok to let all ICMP traffic through firewall?
    ... :ICMP is throwing the baby out with the bathwater and will cause more ... :bother than not blocking anything. ... :I would suggest allowing ICMP Echo and Echo Reply, ...
    (comp.security.misc)