<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/icmp-question/m-p/916792#M1000420</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not believe that a blanket deny of all ICMP is ever a best practice. If there are some ICMP messages that you believe are security weaknesses then block those specific messages. But there are many ICMP messages that have useful (sometimes almost necessary) information that you would give up if you did a deny icmp any any. For example blocking the ICMP message about Fragmentation required but DF set is what frequently breaks Path MTU Discovery.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Sep 2007 13:56:40 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2007-09-24T13:56:40Z</dc:date>
    <item>
      <title>ICMP question</title>
      <link>https://community.cisco.com/t5/network-security/icmp-question/m-p/916791#M1000419</link>
      <description>&lt;P&gt;Hello:&lt;/P&gt;&lt;P&gt;I just wanted to ask opinion, would denying ICMP from host inside the network to the Internet be considered a Best Practice?  If so, could someone tell me why.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:15:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-question/m-p/916791#M1000419</guid>
      <dc:creator>amohammed01</dc:creator>
      <dc:date>2019-03-11T11:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP question</title>
      <link>https://community.cisco.com/t5/network-security/icmp-question/m-p/916792#M1000420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not believe that a blanket deny of all ICMP is ever a best practice. If there are some ICMP messages that you believe are security weaknesses then block those specific messages. But there are many ICMP messages that have useful (sometimes almost necessary) information that you would give up if you did a deny icmp any any. For example blocking the ICMP message about Fragmentation required but DF set is what frequently breaks Path MTU Discovery.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2007 13:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-question/m-p/916792#M1000420</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2007-09-24T13:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP question</title>
      <link>https://community.cisco.com/t5/network-security/icmp-question/m-p/916793#M1000421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would think this would not be a best practice. How would you troubleshoot connectivity issues? For example, you can't connect to &lt;A class="jive-link-custom" href="http://www.cisco.com." target="_blank"&gt;www.cisco.com.&lt;/A&gt; Is Cisco's site down, is you LAN down, is your WAN down, is your ISP down, is your DNS server down? How would you answer these questions if you deny ICMP? If you are thinking of just blocking ICMP for Joe user, I don't think that you would gain anything. You can put QOS on routers to throttle icmp traffic, maybe that is the route &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; to go. Or, you need to be looking at bandwidth issues from Skype, Bit Torrent, and other application-layer filtering.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2007 14:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-question/m-p/916793#M1000421</guid>
      <dc:creator>murray-davis</dc:creator>
      <dc:date>2007-09-24T14:22:13Z</dc:date>
    </item>
  </channel>
</rss>

