Firewall Wizards mailing list archives

Re: ICMP Packets.


From: Darren Reed <darrenr () reed wattle id au>
Date: Wed, 3 Jun 1998 22:46:15 +1000 (EST)

In some email I received from tqbf () pobox com, sie wrote:
[...]
2) Is there a list of ICMP message types that are needed as opposed to
ones that are just used for troubleshooting ( like echo, echo-reply )
that can be blocked without problems.

Not that I know of, but you should remember that for information gathering
purposes, blocking ECHO REQUEST messages is a pretty futile gesture.
[...]

I'd second Perry's comments and mention that you're stopping PMTU from
working, for starters.  Whatever is sending out IP packets should be able
to get the ICMP errors which are returned for those packets.

Darren



Current thread: