ICMP Packets

View Poll Results: Block or ALLOW ICMP packets over public router interfaces?

Voters
9. You may not vote on this poll
  • BLOCK

    6 66.67%
  • ALLOW

    3 33.33%
Results 1 to 5 of 5

Thread: ICMP Packets

  1. #1
    Registered User
    Join Date
    Nov 2000
    Location
    Pittsburgh, PA, USA
    Posts
    239

    ICMP Packets

    Just curious about how you handle ICMP packets (most commonly ping and trace route) on your public router interfaces.

    I see two sides to the decision to block ICMP packets:

    1. Block them, as they let people know that you are "there".
    2. NO!!! Don't block because it becomes a pain to test for connectivity remotely.

    Thanks!


    BB

  2. #2
    Registered User CeeBee's Avatar
    Join Date
    Nov 2002
    Location
    USA
    Posts
    2,494
    I have it enabled, easier to see what is going on and where when I do a ping or tracert. However, everything else is locked down and the password is complex enough for the peace of my paranoid mind.

  3. #3
    Registered User DocPC's Avatar
    Join Date
    Sep 2000
    Location
    Coeur d'Alene, ID
    Posts
    2,900
    Lots of ISP's require that you allow ICMP packets........

  4. #4
    Registered User silencio's Avatar
    Join Date
    Sep 2000
    Location
    Savannah
    Posts
    3,960
    My old boss went to Network Associates for security training a few years back. They showed him a number of ways ICMP is used to break into a network. The coolest thing was a 'magic door' that opened a port when you hit the port with a sequence of different sized ICMP packets.

    Jist of the story/conference was that ICMP is at best unsecure and at worst a menace.

    The fact that an ISP would require ICMP is a strong indication of their technical knowledge. It's sad

  5. #5
    Geezer confus-ed's Avatar
    Join Date
    Jul 1999
    Location
    In front of my PC....
    Posts
    13,087
    Quote Originally Posted by DocPC
    Lots of ISP's require that you allow ICMP packets........
    Well yeah ... but not from the entire bloody internet , only trusted/required ips ...

    So that tells me there ought to be a 3rd 'much better' option in the poll - only allow icmp to/from trusted ips & block the rest

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •