Common operational misconceptions

Chuck Anderson cra at WPI.EDU
Wed Feb 15 23:02:58 UTC 2012


On Wed, Feb 15, 2012 at 04:51:44PM -0600, Anton Kapela wrote:
> On Wed, Feb 15, 2012 at 4:36 PM, Chuck Anderson <cra at wpi.edu> wrote:
> > ICMP is bad, and should be completely blocked for "security".
> 
> I can't tell if this reply is to say "this ought to be done" or if
> "this is often done, and should not be."
> 
> Clarify?

This thread is about misconceptions.  What I said was a common
misconception that "all ICMP should be blocked for security reasons".
In reality, some kinds of ICMP are REQUIRED for proper functioning of
an internetwork for things like Path MTU Discovery (ICMP Fragmentation
Needed/Packet Too Big).  Other kinds of ICMP are good to allow for
being nice to the users and applications by informing them of an error
immediately rather than forcing them to wait for a timeout (ICMP
Destination Unreachable).




More information about the NANOG mailing list