Firewall Wizards mailing list archives

Re: ICMP Packets.


From: "Perry E. Metzger" <perry () piermont com>
Date: Tue, 02 Jun 1998 12:16:10 -0400


Henry Hertz Hobbit writes:
Forget the list . . . as it has been said by MANY that have
said it before, if you don't need it, block it, both ways. In
other words, this applies to *everything*. If you don't NEED
the ICMP packets (all of them, not just the echo/echo-reply)
to go out, block them.

As I've indicated in another message, blocking all ICMP is actually
very bad. (See that message for details.)

.pm



Current thread: