Firewall Wizards mailing list archives

Re: blocking all ICMP at firewalls


From: Brian Mitchell <brian () firehouse net>
Date: Fri, 17 Oct 1997 22:04:45 -0400 (EDT)

On Wed, 15 Oct 1997, Jyri Kaljundi wrote:


How should ICMP handled correctly at the firewall? The thing I want to
know is if I block all ICMP at firewalls external interface, what are the
things that will break? In some places I want to block both all ICMP to
the firewall external interface and all ICMP going through the firewall to
internal network. And since that will deny incoming echo-reply also, I
think I would deny all outgoing ICMP also. Now what will happen and is
this kind of configuration allowed?

ping and traceroute will immediately not work. You wont be able to get
stuff like unreachables. Possitive side: it becomes impossible to udp scan
your network (intruder doesnt get port unreachables means he can't know
which udp ports are listening).


How important are ICMP source quench, time exceeded and parameter problem?
In theory what I think will happen is there will be cases where one side
is sending too much information which the other side will not receive
(because of source quench not allowed they can not tell each other to slow
down). And there might be cases where one side is down and we do not get
host unreachable in certain time, but we could live with that, most
services still can be manually stopped. 

Most traffic is TCP. Now slowing down means traffic will probably be
dropped. TCP retransmits, so it really is not a big problem. Time exceeded
is not really needed (aside from traceroute, etc) under ordinary
circumstances.


And will I get angry network administrators shouting at me because ICMP
should be always allowed on Internet and I am breaking things?

I doubt it.





Current thread: