Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] Ping vs www server



Josh Glover writes:

 > Yes, I do. I consider turning off ICMP a good tradeoff, because being
 > able to ping

But ICMP isn't just ping.  Since 2001 or so things have been a lot
better, but up to that point I had a lot of trouble with some sites
that wanted weird MTU, or with tunnelled protocols, etc.

IMO if you're going to firewall ICMP, you really ought to only pass
stuff through application gateways and proxies.  No direct connects
between inside and outside at all....



Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links