Gentoo Archives: gentoo-security

From: Andy Smith <andy@××××××××××.net>
To: "gentoo-security@×××××××××××××." <gentoo-security@l.g.o>
Subject: Re: [gentoo-security] firewall suggestions?
Date: Fri, 09 Jan 2004 02:21:58
Message-Id: 20040109021917.GR1665@lug.org.uk
In Reply to: Re: [gentoo-security] firewall suggestions? by Frank Gruellich
1 On Thu, Jan 08, 2004 at 05:55:26PM +0100, Frank Gruellich wrote:
2 > * Troy Farrell <troy@×××××××××××.com> 8. Jan 04
3 > > Chain allow-icmp-traffic (2 references)
4
5 [...]
6
7 > > REJECT icmp -- anywhere anywhere
8 >
9 > The default answer of REJECT ist port unreachable. I always wondered,
10 > if this is a good way to answer to a question in a protocol with no
11 > ports. Shouldn't you answer with ICMP protocol unreachable maybe?
12
13 I thought that ICMP should never be answered with ICMP? So the
14 correct action would be DROP in this case.
15
16 --
17 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] firewall suggestions? Frank Gruellich <frank@××××××××××××.org>