cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Ask the Expert- SD-WAN

1557
Views
0
Helpful
1
Replies
Beginner

If we block ICMP from outside to Inside what are the disadvantages

anyone know about the topic

1 REPLY 1
Highlighted
Contributor

Re: If we block ICMP from outside to Inside what are the disadvantages

immubhai-


if you have an ISP that uses icmp to check if your node is up, then you can use an ACL to allow that one address, otherwise, the best practice would be to allow only echo reply, time-exceeded and unreachable.  I personally try to reduce my external surface area probing by blocking all access from the foreign (to my location) based on IANA addressing blocks.  this is by no means an exact science since addressing from foreign ranges is often given to businesses in the US.  This is my 2 cents, hope it helps.


Vince