Great Circle Associates Firewalls
(February 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewalls replying with ICMP packets.
From: mcr @ milkyway . com (Michael Richardson)
Organization: Milkyway Networks Corporation
Date: 28 Feb 1995 12:22:41 -0500
To: firewalls @ greatcircle . com
Distribution: milkyway
Newsgroups: milkyway.mail.firewalls
References: <199502281419 . GAA06017 @ miles . greatcircle . com> <9502281621 . AA10860 @ tidtest . total . fr>

In article <9502281621 .
 AA10860 @
 tidtest .
 total .
 fr>,
Michel Lavondes <lavondes @
 tidtest .
 total .
 fr> wrote:
>If you have a filtering router as (part of) your firewall, you're limited

  Actually, anyone that does extensive kernel modifications or
implements some policy in the kernel might be able examine a possible
socket *before* replying to the TCP SYN packet. I've been thinking
about this kind of thing a bit.

>A related question is, should your firewall send back anything at all or
>should you leave the sender wondering what happened to his nastygrams ?

  Consider the case where the IP source address is faked, and the
address being faked is behind a 14.4k link. They aren't attacking
*you* they are attacking the guy behind the 14.4k by having *you*
tie up all their bandwidth.
  




-- 
   :!mcr!:            |     <A HREF="http://www.milkyway.com/";>Milkyway Networks Corporation</A>
   Michael Richardson |   Makers of the Black Hole firewall 
 NCF: aa714 || xx714  | +1 613 566-4574 ... mcr @
 milkyway .
 com
 Home: <A HREF="http://www.sandelman.ocunix.on.ca/People/Michael_Richardson/Bio.html";>mcr @
 sandelman .
 ocunix .
 on .
 ca</A>. PGP key available.


References:
Indexed By Date Previous: Re: fragmented packets and packet filters.
From: Ted Doty <ted @ kgbvax . network . com>
Next: Re: fragmented packets and packet filters.
From: jon @ london . csd . harris . com (Jon Shallow)
Indexed By Thread Previous: Re: Firewalls replying with ICMP packets.
From: lavondes @ tidtest . total . fr (Michel Lavondes)
Next: Re: Firewalls replying with ICMP packets.
From: dorian @ oxygen . house . gov (Dorian Deane)

Google
 
Search Internet Search www.greatcircle.com