Re: Types of ICMP Used by DC?

Tech-Archive recommends: Fix windows errors by optimizing your registry



"Ryan Hanisco" <RyanHanisco@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:67019A97-0A96-47BC-9996-35E4A211D225@xxxxxxxxxxxxxxxx
Will,

DCs use ICMP Ping for a number of things and will need the ICMP types that
ping requires. Of course, the most common will be echo and echo reply,
but
the others will be needed for failure or redirect status.

Other than that, you'll see no other "odd" ICMP traffic.

Usually DCs are connected on LAN, WAN, or VPN circuits that are considered
part of the Internal network so so filter very little. If you are
concerned
about blocking specific ICMP types, I would be afraid that you might have
a
bad design on your hands -- or at least an overly complicated one.

Since we are stuck with Windows Firewall, and Windows Firewall by default
does block most types of ICMP, I'm simply asking the question which types
should I unblock.

If your answer is "unblock them all because they all might be used," then
okay.

--
Will


.



Relevant Pages

  • Re: IPTables Critique
    ... ICMP Codes: ... The other ICMP types are mostly just trouble for a home user, ... Here is is from iptables -p icmp --help ... I would drop all icmp except for the unreachables (destination ...
    (comp.security.firewalls)
  • Re: ICMP packets?
    ... ICMP is used to diagnose problems. ... sometimes to tell your host that you cannot reach parts of a network. ... I allow every ICMP types besides 8. ... Subject: ICMP packets? ...
    (comp.security.firewalls)
  • Re: Safe ICMP Types?
    ... >> What ICMP types can I safely let in and out of my PC without degrading ... > should be allowed in/out to your ISP IPs ONLY. ... ICMP 0 and 8 are good and necessary at ... place a limit on echo request that's incoming. ...
    (comp.security.firewalls)
  • Re: How do they do it?
    ... > Sounds like they are disallowing it at the router ot firewall level. ... Traceroute uses ICMP. ... Ports are for TCP and UDP. ... but ICMP filtering is based on "ICMP Types" ...
    (comp.security.firewalls)
  • Re: Questions on ipf in SCO 5.0.7
    ... 20.20.20.0/24 as our local LAN. ... Why not drop all ICMP? ... Type 0 - Echo Reply - this is the Echo reply from the end station ... So if I change icmp-type 0 to icmp-type 8 in the three lines you cite, ...
    (comp.unix.sco.misc)