10-26-2001 02:36 PM - edited 03-08-2019 08:58 PM
I am interested in other Security tech's opinion and policy on allowing outbound ICMP traffic through a firewall to the internet - to do or not to do? That is the question.
And why. And if you have any supporting documentation links to your opinion and/or policy.
Thank you,
10-29-2001 07:45 PM
ICMP Message Types to Allow Outbound at the Perimeter Router/Firewall
Message Types
Number Name
4 source quench
8 echo request (ping)
12 parameter problem
Table 5:
ICMP Message Types to Allow Inbound at the Perimeter Router/Firewall
Message Types
Number Name
0 echo reply
3 destination unreachable
4 source quench
11 time exceeded
12 parameter problem
10-29-2001 08:01 PM
The reason behind limiting ICMP traffic is to 'hide' your hosts as much as possible for a potential hacker. What he/she cannot see, he/she will likely ignore. Security by obscurity!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide