Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 21 Sep 1999 09:16:21 -0700 (PDT)
From:      "Rodney W. Grimes" <rgrimes@gndrsh.dnsmgr.net>
To:        hvoers@anp.nl (Henk van Oers)
Cc:        brian@sys.com.sg (Brian Tan), freebsd-ipfw@FreeBSD.ORG
Subject:   Re: what is 'ICMP:3.13' ?
Message-ID:  <199909211616.JAA63174@gndrsh.dnsmgr.net>
In-Reply-To: <Pine.QNX4.4.10.9909210923530.19183-100000@ns.anp.nl> from Henk van Oers at "Sep 21, 1999 09:40:35 am"

next in thread | previous in thread | raw e-mail | index | archive | help
> On Tue, 21 Sep 1999, Brian Tan wrote:
> 
> > Henk van Oers wrote:
> > > 
> > > 
> > > "Tried the following"? Did you know what you where doing?
> > > Isn't the Cisco wrong configured?
> > > 
> > The Cisco does have IGRP enabled. Is there any problem allowing the
> > protocol packet through? or should the IGRP be disabled in the Cisco?
> 
> I do not see the use of "private interior gateway protocol" on a public
> interface, so why allow the packets.
> And if the Cisco has no  one to talk to, why litter the LAN?
> When you "tried" the allow rule, I was thinking of why not try to disallow
> it? The ipfw rules are there to enable what you need and not to let
> through what you don't know. Isn't it?

I would also contact the administrator responsible for that Cisco beforing
doing any of the above.  There may be a very good reason that IGRP is
enabled.  If your this is an ISP supplied unit you should contact them
about it, they may be using IGRP over the WAN link to maintain your
conectivity and turing it off my disconnect you.


-- 
Rod Grimes - KD7CAX - (RWG25)                    rgrimes@gndrsh.dnsmgr.net


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ipfw" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199909211616.JAA63174>