Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewalls replying with ICMP packets.
From: mulligan @ incog . com
Date: Thu, 02 Mar 95 00:28:45 MST
To: Brent @ GreatCircle . COM (Brent Chapman)
Cc: lavondes @ tidtest . total . fr, avalon @ coombs . anu . edu . au (Darren Reed), firewalls @ greatcircle . com (fw)
In-reply-to: Your message of "Wed, 01 Mar 95 18:10:27 PST." <v02110113ab7ad7f7a67e @ [198 . 102 . 244 . 36]>
Reply-to: mulligan @ incog . com

> >A related question is, should your firewall send back anything at all or
> >should you leave the sender wondering what happened to his nastygrams ?
> 
> I don't think the filtering router should send back ICMP messages in
> response to packets dropped by filtering.
> 

I disagree.  I think that this should be configurable.  If for some
reason you want to send icmp's on a per rule/port/service and per
interface basis, you should be able.  In addition, you should be able to
set the type of unreachable message that you send.

> Second, your filters shouldn't get triggered that often anyway.  They're
> only going to be triggered by things that violate your security policy, and
> there just shouldn't be many such connections.  Letting these few attempted
> connections simply time out isn't going to cause that many more packets to
> flow as things retry before they time out.  Every packet dropped by
> filtering here at GreatCircle.COM is logged; it amounts to a handful of
> packets per day (usually less than a dozen).

I have seen a couple of sites that have continued to send packets for
days, even though a firewall was silently dropping the packets.  A
simple icmp host unreachable sent back stopped it.


As long as it is flexible and configurable, you should have the option
to send back icmps.

	geoff



References:
Indexed By Date Previous: Re: something else about sendmail
From: Brent @ GreatCircle . COM (Brent Chapman)
Next: Re: Firewalls replying with ICMP packets.
From: Brent @ GreatCircle . COM (Brent Chapman)
Indexed By Thread Previous: Re: Firewalls replying with ICMP packets.
From: Brent @ GreatCircle . COM (Brent Chapman)
Next: Re: Firewalls replying with ICMP packets.
From: Brent @ GreatCircle . COM (Brent Chapman)

Google
 
Search Internet Search www.greatcircle.com