Great Circle Associates Firewalls
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: internal filtering router - filter config?
From: Darren Cromer <DarrenCr @ Attachmate . com>
Date: Tue, 7 Jan 1997 06:41:49 -0800
To: "'Ricardo Alvarado'" <ralvarado @ avantel . com . mx>, "'firewalls @ GreatCircle . COM'" <IMCEAX400-c=MX+3Ba=+20+3Bp=AVANTEL+3Bo=MTYEHQ+3Bdda+3ASMTP=firewalls+40GreatCircle+2ECOM+3B @ Attachmate . com>

Why ICMP?  Im curious what inherent risk that would present.

I too am setting up a screening firewall, but I want to allow pings to
traverse the external router. (any advice on how to filter all ICMP
except
pings?)

>----------
>From: 	Ricardo Alvarado[SMTP:ralvarado @
 avantel .
 com .
 mx]
>Sent: 	Friday, January 03, 1997 10:20 AM
>To: 	firewalls @
 GreatCircle .
 COM
>Subject: 	Re: internal filtering router - filter config?
>
>>What type of things would you filter on the internal router? or even
>>the external router? I am going to be installing a firewall real soon
>>and would really appreciate any help.
>>
>>-steve.
>>matkoski @
 dreamscape .
 com
>
>In your external router you'd block any ICMP traffic going back and
>forth, as well as any packets bearing one of your internal IP addresses,
>as a source address, especially if these are going INTO your protected
>network. Also, kill telnets, fingers, snmp and snmp trap. Actually, kill
>any ports that your users will not be using, andl leave just mail, web,
>ftp, etc.
>
>ricardo
>ralvarado @
 avantel .
 com .
 mx
>
>



Follow-Ups:
Indexed By Date Previous: Re: internal filtering router - filter config?
From: lists @ lina . inka . de (Bernd Eckenfels)
Next: Help in any of the folowing if at all possible
From: "Sean Miller" <miller @ id . co . zw>
Indexed By Thread Previous: Re: internal filtering router - filter config?
From: lists @ lina . inka . de (Bernd Eckenfels)
Next: Re: internal filtering router - filter config?
From: ormonde @ trem . cnt . org . br (Rodrigo Ormonde)

Google
 
Search Internet Search www.greatcircle.com