Firewall Wizards mailing list archives
Re: ICMP blocking on PIX .4.4.1
From: lk-m-wizards () bigears solsoft com (Lorens Kockum)
Date: 9 May 2000 08:11:43 -0000
On firewall-wizards GibsonB () gruntal com wrote:
This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. I don't agree with this. ICMP is an invaluable tool for diagnostics. If you shut it down then you are limiting your ability to troubleshoot problems.
Agreed.
What you want to do is allow ICMP to go out but not to come in. Ideally what you want to do is allow certain types of ICMP out(ie Echo requests) and only certain types of ICMP to come in(ie Echo Reply, Time exceeded, unreachable). This is not easily done in a router.
I find it extremely easy. YMMV. What /is/ difficult, well, what is impossible without a stateful engine on your filtering device, is blocking, say, incoming ICMP packets that do not correspond to an actual session. The same thing applies to connected and to connectionless protocols, actually ... the difference being that routers today recognize the TCP established bits and can thus control who initiates the connection. To do that with a connectionless protocol such as, say, outgoing UDP DNS requests from any port, needs a stateful filtering engine.
Current thread:
- Re: ICMP blocking on PIX .4.4.1 Jim Seymour (May 04)
- <Possible follow-ups>
- Re: ICMP blocking on PIX .4.4.1 User nawk (May 04)
- Re: ICMP blocking on PIX .4.4.1 Lorens Kockum (May 12)
- Re: ICMP blocking on PIX .4.4.1 dominik . ratajski (May 05)
- RE: ICMP blocking on PIX .4.4.1 GibsonB (May 05)
- RE: ICMP blocking on PIX .4.4.1 R. DuFresne (May 12)
- RE: ICMP blocking on PIX .4.4.1 Henry B. Tindall, Jr. (May 12)
- Stefan Savage : Hacking the TCP stack R. DuFresne (May 12)
- Re: Stefan Savage : Hacking the TCP stack Frederick N. Chase (May 17)
- Re: ICMP blocking on PIX .4.4.1 Lorens Kockum (May 12)
- RE: ICMP blocking on PIX .4.4.1 GibsonB (May 12)
- RE: ICMP blocking on PIX .4.4.1 Jeff B Boles (May 15)
- RE: ICMP blocking on PIX .4.4.1 David Ashwood (May 15)
- RE: ICMP blocking on PIX .4.4.1 GibsonB (May 15)