Re: Ok to let all ICMP traffic through firewall?
From: Bob Eager (rde42_at_spamcop.net)
Date: 09/23/05
- Next message: Peter: "Re: Ok to let all ICMP traffic through firewall?"
- Previous message: Franklin: "Ok to let all ICMP traffic through firewall?"
- In reply to:(deleted message) Leythos: "Re: Ok to let all ICMP traffic through firewall?"
- Next in thread: Walter Roberson: "Re: Ok to let all ICMP traffic through firewall?"
- Reply: Walter Roberson: "Re: Ok to let all ICMP traffic through firewall?"
- Reply:(deleted message) Leythos: "Re: Ok to let all ICMP traffic through firewall?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 22 Sep 2005 22:30:27 GMT
On Thu, 22 Sep 2005 22:19:07 UTC, Leythos <void@nowhere.lan> wrote:
> In article <96D9EC61DFA1E71F3M4@66.250.146.159>, no_thanks@mail.com
> says...
> > My question is Should a firewall let all ICMP traffic through because
> > there is no real risk if they do?
>
> The common sense rule is to LET NOTHING IN that doesn't have a good
> reason to be let in.
In practice, you need to let a few ICMP messages through, then. For
example, source quench and destination unreachable.
-- [ 7'ism - a condition by which the sufferer experiences an inability to give concise answers, express reasoned argument or opinion. Usually accompanied by silly noises and gestures - incurable, early euthanasia recommended. ]
- Next message: Peter: "Re: Ok to let all ICMP traffic through firewall?"
- Previous message: Franklin: "Ok to let all ICMP traffic through firewall?"
- In reply to:(deleted message) Leythos: "Re: Ok to let all ICMP traffic through firewall?"
- Next in thread: Walter Roberson: "Re: Ok to let all ICMP traffic through firewall?"
- Reply: Walter Roberson: "Re: Ok to let all ICMP traffic through firewall?"
- Reply:(deleted message) Leythos: "Re: Ok to let all ICMP traffic through firewall?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|