Great Circle Associates Firewalls
(March 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Attempt to finger through firewalls causes hangup via ICMP unreachable...
From: jpf @ mig . com (Jack Flory)
Date: Wed, 23 Mar 1994 07:08:57 -0700 (MST)
To: rens @ wintermute . imsi . com
Cc: firewalls @ greatcircle . com
In-reply-to: <9403221250 . AA29573 @ webster . imsi . com> from "Rens Troost" at Mar 22, 94 07:50:21 am

>
>
>>>>>> On Mon, 21 Mar 1994 16:41:42 -0800, Andrew Purshottam
>  andy> <andy @
 autodesk .
 com> said: Content-Length: 925
>
>  andy> what is happening is that the paranoid cisco is returning ICMP
>  andy> unreachable for my companies net, and this is causing all
>	...
>  andy> squish but needing only a finger to activate? Is there any
>  andy> easy way to prevent this behavior?
>
>use cisco's interface command 'no ip unreachables' on the border
>router's outer interface. That should fix it.
>


Yes, this will screen the ICMP packets.  The down side is that all
ICMP Unreachables would be screened, causing true unreachable connections
to appear to hang until the connection timed out.  If the cause of
Andy's problem is the kernel bug, an OS upgrade is probably the
best solution.


Follow-Ups:
References:
Indexed By Date Previous: show me?
From: turching @ mammoth . postech . ac . kr (Jeon Young-min(91))
Next: Re: Attempt to finger through firewalls
From: "Ronald A. Jarrell" <jarrell @ vtserf . cc . vt . edu>
Indexed By Thread Previous: Re: Attempt to finger through firewalls causes hangup via ICMP unreachable...
From: Rens Troost <rens @ webster . imsi . com>
Next: Re: Attempt to finger through firewalls causes hangup via ICMP unreachable...
From: Rens Troost <rens @ lorax . imsi . com>

Google
 
Search Internet Search www.greatcircle.com