Re: Ok to let all ICMP traffic through firewall?

From: Bob Eager (rde42_at_spamcop.net)
Date: 09/24/05


Date: 24 Sep 2005 09:35:02 GMT

On Sat, 24 Sep 2005 02:08:27 UTC, Leythos <void@nowhere.lan> wrote:

> In article <dh26m7$rrh$1@lucy.duncodin.org>, mike@duncodin.org says...
> > In article <MPG.1d9e1b2addd7c42198a107@news-server.columbus.rr.com>,
> > Leythos <void@nowhere.lan> wrote:
> > >Here is the RFC's introduction to the ICMP - and it even includes
> > >statements that indicate that it's not foolproof, some datagrams may
> > >still be lost, and that other protocols may not use it, that
> > >communications can be unreliable.....
> >
> > The passages you refer to are talking about _IP_ and the use of ICMP
> > packets to report errors situations in IP. The words not foolproof etc
> > refer to IP not ICMP.
>
> Which does not change the fact that I can limit ICMP to my non-partners
> without impact on our communications.

Well, you think you can.

-- 
[ 7'ism - a condition by which the sufferer experiences an inability
to give concise answers, express reasoned argument or opinion.
Usually accompanied by silly noises and gestures - incurable, early
euthanasia recommended. ]


Relevant Pages