5 ms·
Some people don't want to deal with ping floods, sweeps, ICMP tunneling issued and the whole ICMP redirect attacks?
by temp667 5y ago
Some people don't want to deal with ping floods, sweeps, ICMP tunneling issued and the whole ICMP redirect attacks?
- korethr 5y agoThere's a difference between blanket blocking all ICMP and selectively blocking or rate-limiting a subset of ICMP messages according to an accurate threat model for your various networks. The latter, properly done, is unlikely to break MTU discovery or your own ability to troubleshoot and monitor your own hosts/networks. The former is what makes network engineers want to eviscerate you and use your gut as patch cables.
- labawi 5y agoIMO, the crux of the issue is that kind-of-necessary and dangerous functionality is commingled in "ICMP", with no trivial way to separate the two. With usual TCP and UDP, you block by default, allow outgoing, allow replies and your internet works (consumer defaults). If you want, you allow specific incoming ports and it's good enough for most use cases. It's almost trivial to configure a reasonable basic firewall, and you can learn all you need in 5-10 minutes. With ICMP, there is this long list of types and subtypes, some of which sound dangerous while others necessary. Which ones should you block and which ones should you allow? Do you expect everyone to create an accurate threat model? People have lives. So, some people end up blocking ICMP and internet "works" except .. of course it doesn't.
- oarsinsync 5y ago> Do you expect everyone to create an accurate threat model? People have lives. So, some people end up blocking ICMP and internet "works" except .. of course it doesn't. This is the internet eqivalent of dumping your sewage in the lake because it's too difficult to deal with properly. People that do this externalise the costs of their choices onto everyone else, and it takes a bunch of specialists to identify what's happening and educate the problematic network operator, and/or clean up the mess.
- labawi 5y agoIn a way yes, but I think the issue is largely caused by those up the chain that make it hard to deal with. Doing a search on should I block ICMP, or what ICMP to block, answers are: [1] No!!; some security issues; a lot of ICMP should be blocked; suggests further research [2] you should selectively filter; example iptables rule to allow echo; assess evaluate and make your own rules [3] listing of types and RFC recommendations for transit and local traffic So I guess I should take "Should Be Dropped" and "Policy Should be Defined" from [3] and plug them into [2]. Why is it so hard? Why isn't the answer: "No, defaults are safe, no need to block anything", or "Select one of: Endpoint / Site firewall / Internet router; customize if needed"? IMO, this is a mess. This is the ultimate cause of all the sewage, time spent both debugging, and even more on learning what and how to block, configuring it all. Issues like this even hinder IPv6 adoption, because who is going to deal with all the complexity. [1] http://shouldiblockicmp.com/ http://shouldiblockicmp.com/ [2] https://blog.securityevaluators.com/icmp-the-good-the-bad-and-the-ugly-130413e56030 https://blog.securityevaluators.com/icmp-the-good-the-bad-an... [3] https://serverfault.com/questions/981558/which-ipv4-6-icmp-types-should-i-drop-to-block-ping https://serverfault.com/questions/981558/which-ipv4-6-icmp-t...
- oarsinsync 5y ago> In a way yes, but I think the issue is largely caused by those up the chain that make it hard to deal with. > Doing a search on ... answers are: Sorry, "Google search results" are not "up the chain". That's your first mistake. There's a tonne of misinformation in Google search results. It's real hard to identify what's good and what's not if you're not a specialist in the field, so it's easy to fall victim to this and just believe well meaning well written blog posts. Don't do this. When you don't know something, speak to someone who does know about the subject matter at hand. Not anonymous people on the internet, but someone in reality that you can have a conversation with. If it's a topic that's vaguely within the remit of someone you work with, that's a good place to start.