ICMP question

Discussion in 'other firewalls' started by delerious, Sep 12, 2006.

Thread Status:
Not open for further replies.
  1. delerious

    delerious Registered Member

    Joined:
    Jul 16, 2006
    Posts:
    130
    I see some people say that the only outbound ICMP packets you should allow are type 8. But is it necessary to make rules that explicitly allow type 8 and explicitly deny all other types for outbound? If you set up your incoming ICMP rules correctly (let's say only allow incoming types 0, 3, and 11), then could you ever have an ICMP packet leave your system that is not type 8?
     
  2. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    4,020
    Location:
    California
    ICMP type 3 could go out. When I configured my ruleset, there were requests for ICMP type 3 out to my ISP, so I made a custom rule to allow for that. It doesn't occur very often.

    My final ICMP rule denies all other in-out ICMP.

    I haven't had any outbound attempts for other types.


    -rich



    ________________________________________________________________
    "Talking About Security Can Lead To Anxiety, Panic, And Dread...
    Or Cool Assessments, Common Sense And Practical Planning..."
    --Bruce Schneier​
     
  3. delerious

    delerious Registered Member

    Joined:
    Jul 16, 2006
    Posts:
    130
    If a type 3 goes out, it would be in response to something. What kind of incoming packet would trigger a type 3 ICMP packet to go out?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.