Great Circle Associates Firewalls
(May 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: ICMP risks to firewalls
From: rjb @ pop . sunalliance . com (Richard Bignell)
Date: Fri, 10 May 96 10:09:59 BST
To: firewalls @ greatcircle . com
Cc: rjb @ pop . sunalliance . com

Please forgive me if this subject has been discussed before, but I'm
a new recruit to this list.

My query is about ICMP and firewalls - what I need to block and what
I need to allow. I have been told that if a firewall allows ICMP
traffic then it is possible to discover or compromise its routing
tables (and thence fool anti-spoofing rules) - therefore turn it off.
I have also been told that ICMP is used by some routers (incl. our
ISP) to monitor its network and route trip times - therefore turn it
on if you want efficient routing to your firewall from the Internet.

I am aware that there is more than one type of ICMP message, we have
been looking at Firewall-1 and it identifies the following ICMP
services:

      echo-request                      mask-request
      echo-reply                        mask-reply
      info-req                          param-prblm
      info-reply                        source-quench
      redirect                          timestamp
      dest-unreach                      timestamp-reply
      time-exceeded

Which of these would be OK, and which not ?

Any help or comments would be gratefully appreciated.

Richard Bignell
Sun Alliance
rjb @
 pop .
 sunalliance .
 com
[Standard Disclaimer Applies]



Follow-Ups:
Indexed By Date Previous: CACS Conference 96
From: "marc.vael" <marc . vael @ ArthurAndersen . com>
Next: Re: Linux network monitoring
From: Eric Wieling <ewieling @ hephaestus . icorp . net>
Indexed By Thread Previous: CACS Conference 96
From: "marc.vael" <marc . vael @ ArthurAndersen . com>
Next: ICMP risks to firewalls
From: David Bonn <David . Bonn @ sealabs . com>

Google
 
Search Internet Search www.greatcircle.com