Gentoo Archives: gentoo-security

From: Troy Farrell <troy@×××××××××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] firewall suggestions?
Date: Thu, 08 Jan 2004 16:40:29
In Reply to: Re: [gentoo-security] firewall suggestions? by Ryan Voots
# iptables -L allow-icmp-traffic

Chain allow-icmp-traffic (2 references)
target     prot opt source               destination
ACCEPT     icmp --  anywhere             anywhere           icmp time-exceeded
limit: avg 10/sec burst 5
ACCEPT     icmp --  anywhere             anywhere           icmp
destination-unreachable limit: avg 10/sec burst 5
ACCEPT     icmp --  anywhere             anywhere           icmp source-quench
limit: avg 10/sec burst 5
ACCEPT     icmp --  anywhere             anywhere           icmp echo-request
limit: avg 5/sec burst 5
ACCEPT     icmp --  anywhere             anywhere           icmp echo-reply
limit: avg 5/sec burst 5
LOG        icmp --  anywhere             anywhere           LOG level warning
prefix `Bad ICMP traffic:'
REJECT     icmp --  anywhere             anywhere

Something like this?

And the glory of the LORD shall be revealed, and all flesh shall see it
together: for the mouth of the LORD hath spoken it.
Isaiah 40.5

Ryan Voots wrote:
> On Thu, 8 Jan 2004 16:17:49 +0100 "Oliver Schad" <o.schad@×××.de> Add to > Address Book wrote: > >> Probably you think ICMP is dangerous too. There are a lot of brain dead >> admins who blocks ICMP packets and they wonder why connections to some >> websites are broken or if they administrate the packet filter before a >> webserver they wonder why some user grouches they wouldn't get a connection >> to the web server. > > > thats one reason i don't block it, some services and things use it to look > for hosts that are up, what i wish i could do is some type of limit where it > would only send replies to them at a certain rate, just so that a ping -f on > 12 machines to my machine wouldn't cause a huge bandwidth surge from my > machine.
