[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ICMP drop.



Daniel Pittman wrote:
This is a stunningly bad idea, I fear to say. If you drop ICMP
'fragmentation needed', you become a PMTU discovery black hole.

This *will* make your life miserable, as you suddenly can't connect to,
or be connected to from, a large proportion of systems.


Additionally, you make network troubleshooting much harder, and really gain little in the way of security. Filter ICMP selectively, and use rate limiting rather than filtering where possible.

-Josh




Reply to: