Firewall Wizards mailing list archives
Re: How automate firewall tests
From: "Patrick M. Hausen" <hausen () punkt de>
Date: Mon, 21 Aug 2006 18:49:52 +0200
Hi!
Sure, but not many folks are downstream of small MTU serial links anymore, so if you set your external link to frag at 1492 or less (down to the minumum of 576 if you'd like ~100% success,)
Got it. But 576 doesn't guarantee 100% success, even if you have a fair chance ;-) IIRC any IP implementation must be able to receive at least 576 bytes sized frames. But there is no mandation of a minimum path MTU of that size. 256 bytes or something in that order was common on dialup modem links.
But since you control PMTU on your network, you can simply shrink it enough and allow the ICMP traffic between trusted nodes only. Solves the problem.
I was thinking of the not so knowledgable server/firewall admin blocking ICMP without those measures. And, what's so bad about ICMP "df needed" messages? Of course I'm not proposing to allow _all_ types of ICMP through. Regards, Patrick -- punkt.de GmbH Internet - Dienstleistungen - Beratung Vorholzstr. 25 Tel. 0721 9109 -0 Fax: -100 76137 Karlsruhe http://punkt.de _______________________________________________ firewall-wizards mailing list firewall-wizards () listserv icsalabs com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: How automate firewall tests, (continued)
- Re: How automate firewall tests Dave Piscitello (Aug 30)
- Re: How automate firewall tests Richard Golodner (Aug 18)
- Re: How automate firewall tests Marcus J. Ranum (Aug 20)
- Re: How automate firewall tests StefanDorn (Aug 20)
- Re: How automate firewall tests Strabla Ruggero (Aug 20)
- Re: How automate firewall tests Shahin Ansari (Aug 20)
- Re: How automate firewall tests Patrick M. Hausen (Aug 21)
- Re: How automate firewall tests Paul D. Robertson (Aug 21)
- Re: How automate firewall tests Patrick M. Hausen (Aug 21)
- Re: How automate firewall tests Paul D. Robertson (Aug 21)
- Re: How automate firewall tests Patrick M. Hausen (Aug 21)
- Re: How automate firewall tests Paul D. Robertson (Aug 21)
- Re: How automate firewall tests Oliver Humpage (Aug 21)
- Re: How automate firewall tests Marcus J. Ranum (Aug 21)
- Re: How automate firewall tests Isaac Van Name (Aug 21)
- Re: How automate firewall tests Shahin Ansari (Aug 20)
- Re: How automate firewall tests Avishai Wool (Aug 22)
- Re: How automate firewall tests Bill Royds (Aug 21)