Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Sending replies to blocked packets.
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Fri, 7 Jul 1995 20:53:49 +1000 (EST)
To: tli @ cisco . com (Tony Li)
Cc: firewalls @ greatcircle . com
In-reply-to: <199507070932 . CAA27033 @ greatdane . cisco . com> from "Tony Li" at Jul 7, 95 02:32:08 am

In some mail from Tony Li, sie said:
>    Many firewalls/firewall software now support sending back those nice
>    ICMP messages saying that the detination host was unreachable.  While
>    this is nice for those in and outside, is there any structuring beyond
>    the simple "host unreachable" ?
> 
> Actually, router requirements, RFC 1812, defines a new ICMP
> Unreachable code: Communication Administratively Prohibited, which is
> the preferred mechanism for filtering routers.   [Coming soon to a
> cisco near you. ;-) ]

Hmmm, a newbie ICMP.

[...]
>    I've managed to get a packet
>    filter designed and supported which sends out FAKE TCP RSTs instead of
>    ICMP unreachables - if told to.  How many RFCs does this break ? :)
> 
> None that I'm aware of.  However, what do you do about UDP?

Still use ICMP...afterall, that's what gets used between hosts with no
intervening firewall..

>    My justification is that if I block certain TCP SYN packets and send back
>    an RST in reply, not only do I stop the connection and send back a nack,
>    but in using TCP's RST, I can usually effect a much quicker nack response
>    than with ICMPs - and much safer too!  
> 
> A host can immediately process the new ICMP unreachable code as a NAK,
> as it is presumed to have a long half-life.

Except, being new, which of the currently deployed TCP/IP stacks will
recognise it for what it is ?  (Including commercial products)

darren


References:
Indexed By Date Previous: Re: NNTP caching proxy
From: Brian Rogers <brogers @ integctr . com>
Next: Re: Sending replies to blocked packets.
From: blymn @ awadi . com . AU (Brett Lymn)
Indexed By Thread Previous: Sending replies to blocked packets.
From: Tony Li <tli @ cisco . com>
Next: Re: Sending replies to blocked packets.
From: blymn @ awadi . com . AU (Brett Lymn)

Google
 
Search Internet Search www.greatcircle.com