Gentoo Archives: gentoo-security

From: Frank Gruellich <frank@××××××××××××.org>
To: "gentoo-security@×××××××××××××." <gentoo-security@l.g.o>
Subject: Re: [gentoo-security] firewall suggestions?
Date: Fri, 09 Jan 2004 02:32:42
Message-Id: 20040109022709.GT4413@home.manuelm.org
In Reply to: Re: [gentoo-security] firewall suggestions? by Andy Smith
1 * Andy Smith <andy@××××××××××.net> 9. Jan 04
2 > On Thu, Jan 08, 2004 at 05:55:26PM +0100, Frank Gruellich wrote:
3 > > * Troy Farrell <troy@×××××××××××.com> 8. Jan 04
4 > > > Chain allow-icmp-traffic (2 references)
5 > > > REJECT icmp -- anywhere anywhere
6 > > The default answer of REJECT ist port unreachable. I always wondered,
7 > > if this is a good way to answer to a question in a protocol with no
8 > > ports. Shouldn't you answer with ICMP protocol unreachable maybe?
9 > I thought that ICMP should never be answered with ICMP? So the
10 > correct action would be DROP in this case.
11
12 Oh, come on, echo request isn't answered with echo reply anymore?
13 Please think, then post. ICMP errors are not answerd, that's right so
14 far.
15
16 Regards, Frank.
17 --
18 Sigmentation fault
19
20 --
21 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] firewall suggestions? Andy Smith <andy@××××××××××.net>