Hi, all!

On Fri, Aug 18, 2006 at 10:26:53AM -0700, Shahin Ansari wrote:

> The doco above says no good firewall should allowe ICMP, ...


Then this document is plainly wrong, IMHO. Which one were you
referring to?

Blocking ICMP completely breaks PMTUD. Which leads to all
sorts of "funny" breakage from the end users point of view.

Regards,
Patrick
--
punkt.de GmbH Internet - Dienstleistungen - Beratung
Vorholzstr. 25 Tel. 0721 9109 -0 Fax: -100
76137 Karlsruhe http://punkt.de
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailma...rewall-wizards