Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: strange behavior
From: "Gregg Earnhart" <ge @ gte . net>
Date: Thu, 13 Feb 1997 05:01:30 -0600
To: "Rafeeq Ur Rehman" <rehman @ lhr . aster . com . pk>, "Dave Sroelov" <dsroelov @ pacbell . net>
Cc: <fw-1-mailinglist @ us . checkpoint . com>, <firewalls @ GreatCircle . COM>

Take a look at the properties tab (platform depends on location). Then look
at Enable ICMP.  This setting is called rule "zero".  The setting allows
First, before last, and last.  I believe it defaults to first. If the
firewall rule base is any----any---drop for the last rule, then the rule
will allow ICMP before it looks at the last rule.  If the setting is set to
last, then the ICMP rule in the properties tab will be the last rule in the
rule set.

Gregg Earnhart  

----------
> From: Rafeeq Ur Rehman <rehman @
 lhr .
 aster .
 com .
 pk>
> To: Dave Sroelov <dsroelov @
 pacbell .
 net>
> Cc: fw-1-mailinglist @
 us .
 checkpoint .
 com; firewalls @
 GreatCircle .
 COM
> Subject: Re: strange behavior
> Date: Thursday, February 13, 1997 12:35 AM
> 
> On Wed, 12 Feb 1997, Dave Sroelov wrote:
> 
> > being somewhat new to FW-1 i have come across something that is a
little
> > strange.  if i set up a policy with one rule that says to reject all
> > packet types from source=any to destination=any and log everything, why
> > does ping still work?
> > 
> > if i specifically add a rule to block icmp packets then ping stops.  i
> > would think that blocking 'all' packet types would block everything
that
> > FW-1 knows about, and it knows about icmp.
> > 
> If you have an application level firewall, it may not stop icmp.
> 
> Rafeeq Ur Rehman
> rehman @
 lhr .
 aster .
 com .
 pk
> 

Indexed By Date Previous: Re: What firewall do I need.
From: Jim Canfield <jcanfiel @ netrunner . net>
Next: e-mail !!!!= HTML \:-| (reply)
From: minaba @ mail1 . ci . chi . il . us (Mark Inaba)
Indexed By Thread Previous: Firewalling X.400
From: Paulo Jorge Delgado <Paulo . Delgado @ bta . pt>
Next: e-mail !!!!= HTML \:-| (reply)
From: minaba @ mail1 . ci . chi . il . us (Mark Inaba)

Google
 
Search Internet Search www.greatcircle.com