[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IPNAT/IPF redirect visibility



On Wed, Jun 06, 2001 at 11:59:37AM -0400, John Pavlakis wrote:

> > > block return-icmp-as-dest(port-unr) in log quick on ep1
> > > proto icmp all group 10
> > 
> > Never do that. Imagine I have the same rule on my firewall and I ping
> > you.
> 
> I already have a keep state entry for outgoing icmp. Would that be ok then?

Yes and no.

I don't think it's RFC-compliant to send an icmp error to an icmp
query, even more to send an icmp error to an icmp error.
Either you send the right icmp answer for the icmp query you got, or
you drop the packet on the floor.

Comments anyone ?

-- 
Rémi



Visit your host, monkey.org