(edit: incorrect explanation deleted)Wow, thanks for your fast reponse, Chris!(/edit)
Quote:
Dropping all of ICMP is a bad thing. Where people get this crazy notion is beyond me. (There is some good ICMP out there!). However dropping just ping is another story.
As I understand it, I had the firewall set up to allow any ICMP related to an already existing connection or any ICMP I sent. Would this let through all the 'good' ICMP while blocking the 'bad' ICMP?
My understanding was that ICMP is bad b/c it can be used to determine the version of linux you're running...but maybe that is just heresay?
Quote:
(Some what related/unrelated note: The more you attempt to drop (aka "blackhole"), the more you look like you have something to hide
Do you think it would be better to set the default policy to reject instead of drop?
Thanks,
-Mike