Re: Ok to let all ICMP traffic through firewall?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Ok to let all ICMP traffic through firewall?

From: Bob Eager <rde42@spamcop.net>
Date: Fri Sep 23 2005 - 02:29:30 CEST

On Thu, 22 Sep 2005 23:13:55 UTC, Leythos <void@nowhere.lan> wrote:

> > In practice, you need to let a few ICMP messages through, then. For
> > example, source quench and destination unreachable.
>
> Wrong, you don't NEED to allow anything. You may FEEL that you do, but
> we've got almost 100 networks that don't allow ICMP or anything else
> inbound and they work just fine, and we'll not change them.

You're wrong. But that's fine. You just carry on.

-- 
[ 7'ism - a condition by which the sufferer experiences an inability
to give concise answers, express reasoned argument or opinion.
Usually accompanied by silly noises and gestures - incurable, early
euthanasia recommended. ]
Received on Thu Sep 29 20:10:17 2005