Firewall Wizards mailing list archives
Re: how to block ICMP tunneling?
From: "Ryan Russell" <Ryan.Russell () sybase com>
Date: Tue, 20 Jul 1999 11:23:24 -0700
In message <3988F0001E0BD31192180090274077D0702CC0 () sj-msg01 altera com>, Kyle S tarkey writes:I was under the impression that ICMP should be blocked coming from the outside. I can't think of any reason you would want some one from the outside PINGing, TRACRTing or otherwise Probing your internal network for active hosts. IMHO you should simply block the entire proctocol from the outside.If you do, you break Path MTU, which can disrupt communications to many sites.
Indeed. I've really come to dislike ICMP. It's just too "out of band" for it's own good. Does anyone know if this is being improved in IPV6? (Not that it will neccessarily do any good, but I don't know where else one would "fix" it.) For Path MTU discovery, shouldn't there be an explicit way to get the exact MTU discovered? Say... as the SYN packet travels to the server, have the routers decrement a "client path MTU" field to the smallest MTU along the way. Same with the SYN-ACK on the way back with a "server path MTU". There would have to be a way for it to change in the middle, too, for re-routes. Same for things like port unreachables.. should be part of the connection, no? Easier to see for TCP vs. UDP. Something similiar to the OOB data, perhaps? I've always been uncomfortable that some random IP along the path of my connection has the "right" to tell me something is "wrong" even when there is no obvious relationship to that connection. Screws up NAT, too. :) Ryan
Current thread:
- RE: how to block ICMP tunneling?, (continued)
- RE: how to block ICMP tunneling? Jason Diesel (Jul 19)
- RE: how to block ICMP tunneling? Kevin Steves (Jul 26)
- RE: how to block ICMP tunneling? Kyle Starkey (Jul 19)
- Re: how to block ICMP tunneling? Joseph S D Yao (Jul 20)
- Re: how to block ICMP tunneling? Chris Brenton (Jul 20)
- Re: how to block ICMP tunneling? carson (Jul 21)
- Re: how to block ICMP tunneling? Geva Patz (Jul 20)
- RE: how to block ICMP tunneling? Marcus J. Ranum (Jul 19)
- Re: how to block ICMP tunneling? Steven M. Bellovin (Jul 20)
- RE: how to block ICMP tunneling? Ben Nagy (Jul 20)
- Re: how to block ICMP tunneling? Ryan Russell (Jul 21)
- Re: how to block ICMP tunneling? Dru (Jul 26)
- RE: how to block ICMP tunneling? Jason Diesel (Jul 21)
- Re: how to block ICMP tunneling? Adam Shostack (Jul 23)
- RE: how to block ICMP tunneling? Marcus J. Ranum (Jul 23)
- Re: how to block ICMP tunneling? Sean Costello (Jul 29)
- Re: how to block ICMP tunneling? Sean Costello (Jul 29)
- Fw: how to block ICMP tunneling? Sean Costello (Jul 30)
- RE: how to block ICMP tunneling? Jason Diesel (Jul 19)