From owner-freebsd-security Sun Feb 24 7:30:24 2002 Delivered-To: freebsd-security@freebsd.org Received: from scorpio.drkshdw.org (user4.net011.fl.sprint-hsd.net [207.30.203.4]) by hub.freebsd.org (Postfix) with ESMTP id 055E537B404 for ; Sun, 24 Feb 2002 07:30:21 -0800 (PST) Received: from scorpio (jeff.home.lan [192.168.134.2]) by scorpio.drkshdw.org (8.11.6/8.11.6) with SMTP id g1OFUGK07834; Sun, 24 Feb 2002 10:30:16 -0500 (EST) (envelope-from scorpio@drkshdw.org) Message-ID: <001101c1bd48$2df35020$0286a8c0@home.lan> From: "Jeff Palmer" To: "Dag-Erling Smorgrav" Cc: References: <003b01c1bcda$d4f06020$0286a8c0@home.lan> Subject: Re: Couple of concerns with default rc.firewall Date: Sun, 24 Feb 2002 10:30:23 -0500 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org DES, Maybe you fail to see my point. I was wondering if there was a reason the FreeBSD team has decided not to allow certain ICMP's by default. I'm perfectly aware of how to change the rules to do what I want. I was asking if there was a reason for this decision, or if it was an oversight. ----- Original Message ----- From: "Dag-Erling Smorgrav" To: "Jeff Palmer" Cc: Sent: Sunday, February 24, 2002 7:16 AM Subject: Re: Couple of concerns with default rc.firewall > "Jeff Palmer" writes: > > Is there any reason in particular, that ALL icmp traffic is denied > > by default, except for using the 'open' ruleset? > > The default rule #65535 is "deny ip from any to any". Wouldn't you be > surprised if this *didn't* block all ICMP packets? > > Just add the following early on in your firewall ruleset: > > allow icmp from any to any icmptype 0,3,8,11 > > preferably *after* any anti-spoofing rules. > > DES > -- > Dag-Erling Smorgrav - des@ofug.org > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message