3 ms·
> I'd say it has a few main facets: - ICMP is dangerous, and needs to be blocked. This is partly true, as there is historically information leakage with ICMP un
by feld 9y ago
> I'd say it has a few main facets: - ICMP is dangerous, and needs to be blocked. This is partly true, as there is historically information leakage with ICMP under certain codes. So blocking all of it is easier than trying to figure out what should be allowed and what should not.
It's actually quite easy to identify which should be allowed and which should not.
ICMP: 0,3,8,11 (echo reply, destination unreachable, echo, time exceeded)
ICMP6: 1,2,3,4,128,129,135,136 (unreachable, packet too big, time exceeded, parameter problem, echo request, echo reply, neighbor solicitation, neighbor advertisement)
See, that wasn't hard. These are the base requirements for you to have a reasonably functional IPv4 network, and the absolute minimum requirements for IPv6 to work properly.
- verri 9y agoBut why filter ICMP at all? I can understand that ICMP allows for covert tunnelling, but by that logic any IP protocol number should be blocked.
- mgsouth 9y agoI think it's more the incoming ICMP that is troublesome, particularly redirect, and to a lesser extent destination unreachable (DOS).
- rasz 9y agoUnder windows you cant whitelist applications allowed to use ICMP, all ICMP traffic originates from deep down ring 0 NT Kernel process.
- feld 9y agobecause some ICMP types are actually dangerous and can be abused
- kevin_nisbet 9y agoAgreed. It's just the argument that gets made for filtering, is we'd rather just filter it all instead of trying to understand what should and should not be filtered.