Re: Ok to let all ICMP traffic through firewall?

From: Mike (NoSpam_at_NoSpam.net)
Date: 09/23/05


Date: Fri, 23 Sep 2005 09:54:10 -0400

On 22 Sep 2005 22:36:09 GMT, abuse@dopiaza.cabal.org.uk (Peter) wrote:

>I would suggest allowing ICMP Echo and Echo Reply (so ping works),

Be sure to deny Echo Request that is sent to the broadcast address for
your subnet (.255 and .0 for /24 subnets). If a malicious person
sends several hundred of those per second, you'll wind up with a lot
of ICMP traffic on your subnet as each host tries to send back the
reply.



Relevant Pages

  • Re: spoofing ip as broadcast
    ... A subnet broadcast is sent out to the MAC address ff:ff:ff:ff:ff:ff ... only hosts in the same subnet will pay attention to the packet; ... As far out as practical that you can arrange, you should filter packets ...
    (comp.security.misc)
  • Re: spoofing ip as broadcast
    ... A subnet broadcast is sent out to the MAC address ff:ff:ff:ff:ff:ff ... only hosts in the same subnet will pay attention to the packet; ... As far out as practical that you can arrange, you should filter packets ...
    (comp.security.misc)
  • Re: Netmasks for dummies
    ... 198.113.64.0-198.113.64.7 is a valid IP block for a /29 subnet. ... number of bits to the network and the remainder to the host. ... 1 is a network address and 1 is a broadcast address. ... address, .15 is the broadcast, .1-.14 are valid host addresses. ...
    (comp.os.linux.misc)
  • Re: spoofing ip as broadcast
    ... What's the diff tween a global broadcast and local broadcast? ... and the broadcast IP address associated with your subnet. ... only hosts in the same subnet will pay attention to the packet; ... All hosts on the local segment will receive the packet and pay attention ...
    (comp.security.misc)
  • Re: browsing Sonicwall VPN box to box
    ... I did some skimming through the VPN chapter on SonicWall's web ... broadcast' checked in Global IPSec Settings? ... Are your subnet masks, local & subnetted remote LAN settings ...
    (comp.security.firewalls)