Security Basics mailing list archives

RE: Removing ping/icmp from a network


From: "Ric Messier" <kilroy () WasHere COM>
Date: Fri, 28 Mar 2008 10:49:52 -0600

Michael Painter writes:

I'm not sure what 'clean' means, but I'm not supposed to see 10/8
addresses on the "Internet".

You're not supposed to be able to get to 10/8 addresses that you don't have
an internal route to. That doesn't mean you won't "see" them. It's not
uncommon for large ISPs to use private addressing inside their network and
you see that from time to time on traceroutes. Depends on what source
address the ICMP message comes from as to how the traceroute displays the
hops.

Ric



Current thread: