OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Patrick Morris (pmorriswilshire.com)
Date: Mon May 20 2002 - 13:02:53 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Blocking all ICMP from outside to inside would allow pings out, but the
    replies to them would be blocked on the way back in.

    To make this work, one would have to allow ICMP echo-request traffic to
    leave the network, and allow ICMP echo-reply traffic to enter.

    On Sun, 19 May 2002, Andrew Bailey wrote:

    > Create a Packet filter rule on your firewall allowing ICMP
    > from internal network to extenal network.
    >
    > Create a second Packet Filter rule on your firewall
    > denying ICMP from the external network to internal network.