LinuxQuestions.org
LinuxAnswers - the LQ Linux tutorial section.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 08-08-2001, 01:36 PM   #1
mikeyt_3333
Member
 
Registered: Aug 2001
Distribution: Red Hat
Posts: 61

Rep: Reputation: 15
Icmp


I manage a webserver, it handles a couple of websites, mail, ftp, ssh. Do I have any need to allow any incoming ICMP?

Also where can I find good information on decoding the packets that are logged by my snort. For example TOS's TTL's etc, I don't know how to interpret those as negative or otherwise. Thanks for any and all help!

Mike.
 
Old 08-09-2001, 05:40 AM   #2
raz
Member
 
Registered: Apr 2001
Location: London
Posts: 408

Rep: Reputation: 31
Simple answer is Yes, disable them all and you'll have network issues. "that's an understatement"

There are 18 types of ICMP messages used on the network.
Some are obsolete others are useful and others are essential.

Here's a quick list of what should be allow and what not.

Type 0 "Echo reply" = allow it
Type 3 "Destination Unreachable" = allow it
Type 4 "Source quench" = allow it
Type 5 "Redirect" = Deny it (only if you have static routes setup on the routers, otherwise allow it)
Type 8 "Echo Request" = Deny it
Type 9 "Route Advertisement" = allow it
Type 10 "Route Solicitation" = Deny it
Type 11 "Time exceeded" = Deny it
Type 12 "Parameter Problem" allow it
Type 13 "Timestamp request" = Deny it
Type 14 "Timestamp reply" = allow it
Type 17 "Address Mask request" = Deny it
Type 18 "Address Mask reply" = Allow it

To understand the logs from snort you'll need to understand TCP/IP and all parts of the OSI.
Then things like TOS and TTL will be clear to you.
Best suggestion is to buy a book on it.

/Raz
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ICMP Programming mgp Programming 3 07-21-2009 03:11 AM
SSH over ICMP? kleptophobiac Linux - Networking 11 11-11-2006 04:09 PM
About ICMP Ephracis Linux - Networking 1 11-22-2004 08:01 AM
ICMP traffic archives/writing ICMP traffic in a file maia_1 Programming 0 07-20-2004 03:43 AM
What is ICMP? codedv Linux - Networking 2 01-04-2004 10:12 AM


All times are GMT -5. The time now is 04:12 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration