Firewall Wizards mailing list archives

ICMP blocking on PIX .4.4.1


From: majordomo <lists () indifference org>
Date: Fri, 28 Apr 2000 07:53:02 -0700


Allowing ICMP (or any connection-less protocol, such as UDP) *through*
the firewall is another issue entirely.  Connection-less protocols are
not safe.  Cannot be made safe.  Other than perhaps allowing syslog
from the router to a syslog host, specifically, I don't see any
particular reason to allow any UDP through a firewall.


Doesn't DNS use udp? As for the icmp issue, I agree with you.


K.J.



Current thread: