Merit Network
Can't find what you're looking for? Search the Mail Archives.
  About Merit   Services   Network   Resources & Support   Network Research   News   Events   Home

Discussion Communities: Merit Network Email List Archives

North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Firewall stateful handling of ICMP packets

  • From: Owen DeLong
  • Date: Wed Dec 03 19:00:56 2003

Actually, any halfway decent firewall allows you to permit certain ICMP
type codes while rejecting others. Not a perfect solution, but, for the
most part, there aren't a lot of fragmentation-needed exploits running
around. (In fact, I'm hard pressed to imagine how a Frag needed packet
for an invalid session could do much of anything).

Owen


--On Wednesday, December 3, 2003 5:12 PM -0500 Sean Donelan <sean@donelan.com> wrote:


You could drop ICMP packets at your firewall if the firewalls properly
implemented stateful inspection of ICMP packets.  The problem is few
firewalls include ICMP responses in their statefull analysis.  So you are
left with two bad choices, permit "all" ICMP packets or deny "all" ICMP
packets.





--
If it wasn't crypto-signed, it probably didn't come from me.

Attachment: pgp00007.pgp
Description: PGP signature




Discussion Communities


About Merit | Services | Network | Resources & Support | Network Research
News | Events | Contact | Site Map | Merit Network Home


Merit Network, Inc.