Home page logo
/

nanog logo nanog mailing list archives

Re: Common operational misconceptions
From: Chuck Anderson <cra () WPI EDU>
Date: Wed, 15 Feb 2012 18:02:58 -0500

On Wed, Feb 15, 2012 at 04:51:44PM -0600, Anton Kapela wrote:
On Wed, Feb 15, 2012 at 4:36 PM, Chuck Anderson <cra () wpi edu> wrote:
ICMP is bad, and should be completely blocked for "security".

I can't tell if this reply is to say "this ought to be done" or if
"this is often done, and should not be."

Clarify?

This thread is about misconceptions.  What I said was a common
misconception that "all ICMP should be blocked for security reasons".
In reality, some kinds of ICMP are REQUIRED for proper functioning of
an internetwork for things like Path MTU Discovery (ICMP Fragmentation
Needed/Packet Too Big).  Other kinds of ICMP are good to allow for
being nice to the users and applications by informing them of an error
immediately rather than forcing them to wait for a timeout (ICMP
Destination Unreachable).


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]