[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: FIREWALL STRATEGY (What do you think?)



On Thu, Apr 29, 1999 at 07:26:18AM +0200, Manel Marin wrote:
> ABOUT TO BE NOT SEEN:
> I have to accept ICMP type 3 packets "destination unreachable", they are
> used to MTA size negotiation, so I will not be completely not seen...

Actually it is MTU. And you will get ICMP Fragmentation needed (type 4) and
a bunch of others. You can deny all of them, but have a look at the log and
analyse the most frequent ones, will get u better performance and lass
"hanging" connections.

Greetings
Bernd


Reply to: