Firewall Wizards mailing list archives
RE: ICMP and Traceroute
From: Houser David DW <david.houser () zcswilm zeneca com>
Date: Tue, 18 May 1999 09:05:45 -0400
A couple of ideas that might help - Depending on your needs for troubleshooting, Traceroute may be just as helpful from the outside towards you. There are a number of sites that allow this, start at http://www.amazing.com/internet/club-traceroute.html As for the PING, maybe you'd consider allowing the inside to initiate a ping outward, then from the outside only allow the Ping Response? This is more palatable than allowing all ICMP opened up both ways. For instance, on a Cisco, this might be internal netwk ------ Rtr --------------- External netwk e.g. 100.100.100.x ACL 101 out access-list 101 permit icmp 100.100.100.0 0.0.0.255 any echo-reply to allow the router to pass back the Ping response from the external network, in response to a Ping that would have been initiated internally. DWH
---------- From: Deepak Vaidya[SMTP:dvaidya () clark net] Sent: Monday, May 17, 1999 1:26 PM To: firewall-wizards () nfr net Subject: ICMP and Traceroute Two more questions that came from the same group who need access to dns outbound. They would like to be able to ping and traceroute external hosts from all the clients. We currently do not allow icmp and traceroute packets in or out bound. We block all those at the router level. The group is responsible for client network and security design and they would like ping and traceroute for troubleshooting networks. Thanks - Deepak
Current thread:
- ICMP and Traceroute Deepak Vaidya (May 17)
- Re: ICMP and Traceroute Robert McMahon (May 19)
- Re: ICMP and Traceroute Deepak Vaidya (May 19)
- Re: ICMP and Traceroute Kevin Steves (May 22)
- Re: ICMP and Traceroute Jan B. Koum (May 23)
- Re: ICMP and Traceroute Kevin Steves (May 23)
- Re: ICMP and Traceroute Robert McMahon (May 19)
- <Possible follow-ups>
- Re: ICMP and Traceroute Ryan Russell (May 18)
- RE: ICMP and Traceroute Houser David DW (May 18)
- RE: ICMP and Traceroute Frank W. Keeney (May 18)
- RE: ICMP and Traceroute David Gillett (May 19)
- RE: ICMP and Traceroute M. Dodge Mumford (May 21)
- Re: ICMP and Traceroute Joseph S D Yao (May 21)
- RE: ICMP and Traceroute David Gillett (May 19)