Merit Network
Can't find what you're looking for? Search the Mail Archives.
  About Merit   Services   Network   Resources & Support   Network Research   News   Events   Home

Discussion Communities: Merit Network Email List Archives

North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: [nsp] known networks for broadcast ping attacks

  • From: Sean Donelan
  • Date: Wed Jul 30 20:05:21 1997

>Well, I've been filtering ICMP for quite a while at my border routers, 
>and other than the occasional braindead sendmail configuration, and
>the fact that Solaris ping can't handle the "Administratively prohibited" 
>return from the IOS filter rule, I've yet to see a major downside.

Under certain conditions filtering all ICMP messages will break
Path MTU discovery.  Check your router vendor's documentation for
information about filtering types of ICMP messages.

-- 
Sean Donelan, Data Research Associates, Inc, St. Louis, MO
  Affiliation given for identification not representation




Discussion Communities


About Merit | Services | Network | Resources & Support | Network Research
News | Events | Contact | Site Map | Merit Network Home


Merit Network, Inc.