Linux Netfilter discussions
 help / color / mirror / Atom feed
From: cc <cc@kdtc.net>
To: Netfilter Group <netfilter@lists.netfilter.org>
Subject: icmp echo requests
Date: Mon, 29 Sep 2003 14:15:51 +0800	[thread overview]
Message-ID: <3F77CE17.30605@kdtc.net> (raw)

Hi,

I've been monitoring the NAT router with pktstat and am a little
perturbed to see quite a lot of icmp echo requests.  Now I've
setup my Linux firewall to reject icmp echo requests.

Is this the right(?)/correct/valid/appropriate thing to do?

Furthermore (just for clarification) using tcpdump, I get incoming
icmp echo requests, but no response from my firewall(good thing
right?.  This means the firewall is dropping/rejecting the
echo requests?


Here is the line from the firewall script:


iptables -A INPUT -i eth0 -p icmp --icmp-type 8 \
        -j REJECT --reject-with icmp-host-unreachable



Btw, I'm quite bothered about the pings.  It doesn't
look right.

-- 








             reply	other threads:[~2003-09-29  6:15 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-09-29  6:15 cc [this message]
2003-09-29  6:55 ` icmp echo requests Louie Miranda
2003-09-29 19:49 ` Jim Carter
2003-09-29 22:51   ` Michael Kearey
2003-09-30  1:26   ` cc
  -- strict thread matches above, loose matches on Subject: below --
2003-10-01 20:13 Daniel Chemko
2003-09-29  4:32 Edmund
2003-10-01 12:58 ` Jamie Harris

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3F77CE17.30605@kdtc.net \
    --to=cc@kdtc.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox