Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: Oliver Schad <o.schad@...>
From: Mark Hurst <mark@...>
Subject: Re: firewall suggestions?
Date: Fri, 9 Jan 2004 19:06:55 +1100
> Sometimes your packets are too big for some parts of the net without 
> fragmenting so you get a message that you should reduce your packet
> size. If you block such messages, you can't connect with the target.
> These messages are delivered by ICMP so blocking of ICMP is very stupid.

No, blocking of "fragmentation required but DF set" ICMP is stupid.

Allowing all ICMP in just to enable PMTU discovery is not required.

regards

--
gentoo-security@g.o mailing list

References:
Re: firewall suggestions?
-- Oliver Schad
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: firewall suggestions?
Next by thread:
Re: firewall suggestions?
Previous by date:
Re: firewall suggestions?
Next by date:
Re: firewall suggestions?


Updated Jun 17, 2009

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.