OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re[3]: icmp problem

From: BigBrother-{BigB3} (bigbrotherbonbon.net)
Date: Fri May 13 2005 - 11:43:21 CDT


On Fri, 13 May 2005, Danil V. Gerun wrote:

> BB> In my NATED (ipfw+natd) lan EVERY internal host (192.168.XX) can ping
> BB> simultaneously any external host and ALL getting their proper ICMP
> BB> replies.
>
> Well, I didn't configure "ICMP NAT" for my LAN, but I'm just
> wondering: what if _some_ internal hosts start pinging one external
> host? Is each of them going to recieve all the icmp replies?..
>
>
>

As I told you If _some_ internal hosts start pinging one external host,
everyone gets their proper answer. They are not going to receive all the
icmp replies. Everyone receives his reply. Use

natd -v

to figure out

Here is a snip:

Out [ICMP] [ICMP] 192.168.???.130 -> 192.108.???.43 8(0) aliased to
            [ICMP] 193.92.???.26 -> 192.108.???.43 8(0)
In [ICMP] [ICMP] 192.108.???.43 -> 193.92.???.26 0(0) aliased to
            [ICMP] 192.108.???.43 -> 192.168.???.130 0(0)

Make some experiments with

natd -v

and you will understand this.

---
Dreams have no limits!
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"