Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 11 Dec 2001 11:17:49 -0300 (ART)
From:      Fernando Gleiser <fgleiser@cactus.fi.uba.ar>
To:        krzysztof <cs052279@yahoo.com>
Cc:        <freebsd-questions@FreeBSD.ORG>
Subject:   Re: IPF Firewall Question
Message-ID:  <20011211111314.R93662-100000@cactus.fi.uba.ar>
In-Reply-To: <20011211140850.14764.qmail@web14801.mail.yahoo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, 11 Dec 2001, krzysztof wrote:

> Hello,
>
>      Are there any security concerns about passing in
> icmp traffic to my network?  I do not use NAT so
> people at best will be able to map out live machines
> on my network.  Is this correct, or should I be
> concerned about possible attacks through ICMP?  The
> only ICMP traffic I pass in is icmp-type 0,8, & 11.

If you let icmp echo to your broadcast address. your network can act as
a "smurf amplifier". See http://www.cert.org/advisories/CA-1998-01.html
for details.


				Fer



> Any pointers are greatly appreciated.
>
> Thank You
> Chris
>
>
> __________________________________________________
> Do You Yahoo!?
> Check out Yahoo! Shopping and Yahoo! Auctions for all of
> your unique holiday gifts! Buy at http://shopping.yahoo.com
> or bid at http://auctions.yahoo.com
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-questions" in the body of the message
>


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011211111314.R93662-100000>