Firewall Wizards mailing list archives
Re: Blocking ICMP with ipchains
From: "Steven M. Bellovin" <smb () research att com>
Date: Mon, 17 Jan 2000 14:56:34 -0800
In message <H0000b6d066815cd@MHS>, peter.schawacker () citicorp com writes:
--openmail-part-14c50c8a-00000001 Content-Type: text/plain; charset=US-ASCII; name="BDY.TXT" Content-Disposition: inline; filename="BDY.TXT" Content-Transfer-Encoding: 7bit How could blocking all ICMP cause a problem? I have worked with two rather large networks that blocked all ICMP at the router level. Were we just lucky not to have any problems?
It's very important to allow 'ICMP Can't Fragment' messages in. Otherwise,
Path MTU (RFC 1191) breaks, and you may find yourself unable to talk to
certain sites. The only reason most people haven't seen this yet is that most
links support 1500-byte MTUs, so the problem isn't triggered. If you have a
smaller MTU somewhere -- for example, if you have an IPsec tunnel -- you won't
be able to talk to some very popular Web sites.
--Steve Bellovin
Current thread:
- Blocking ICMP with ipchains wwebb (Jan 13)
- Re: Blocking ICMP with ipchains Mikael Olsson (Jan 15)
- Re: Blocking ICMP with ipchains Carric Dooley (Jan 16)
- <Possible follow-ups>
- RE: Blocking ICMP with ipchains peter . schawacker (Jan 16)
- RE: Blocking ICMP with ipchains Ryan Russell (Jan 17)
- Re: Blocking ICMP with ipchains Steven M. Bellovin (Jan 17)
- RE: Blocking ICMP with ipchains Richard . Smyth (Jan 17)
- RE: Blocking ICMP with ipchains Staggs, Michael (Jan 18)
