>Maybe I'm just stupid today, but isn't traceroute just a series of ICMP packet
>s
>with a specific Time-To-Live set in stages? And if ICMP packets are allowed,
>how do you block the "traceroute" program?
Traceroute uses UDP packets to a high port number with the TTL incremented by
one for each packet sent. It listens for the ICMP Time Expired packets
returning. That is where it derives the IP addresses of each hop.
Smoot Carl-Mitchell
Texas Internet Consulting
1106 Clayton Lane, Suite 500W
Austin, TX 78723
+1 512 451-6176
Follow-Ups:
References:
|
|