Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Tue Apr 27, 2004 5:52 pm 
Offline
Senior Newbie

Joined: Sat Mar 13, 2004 7:18 am
Posts: 8
The computer 64.62.190.19 attempts to ping and connect to my non-existant web server on host 19 roughly once per minute. That host is neither my DNS server nor my gateway.

I'm guessing this is part of the 'official' linode network, but what does it do and why does it want to contact me? Will I cause any problems if I drop ICMP and port 80 traffic to my linode?

Thanks,
-Mike


Top
   
 Post subject:
PostPosted: Tue Apr 27, 2004 5:56 pm 
Offline
Senior Member
User avatar

Joined: Sun Nov 23, 2003 1:40 pm
Posts: 79
Website: http://www.whitehouse.gov/history/presidents/bc42.html
Dropping all of ICMP is a bad thing. Where people get this crazy notion is beyond me. (There is some good ICMP out there!). However dropping just ping is another story.

(Some what related/unrelated note: The more you attempt to drop (aka "blackhole"), the more you look like you have something to hide, the more interesting your server becomes to the curious ... )

Bill Clinton


Top
   
 Post subject:
PostPosted: Tue Apr 27, 2004 6:04 pm 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
That's a left-over from an old networking issue, which was fixed earlier this year. I'll run through the hosts and remove it from the ones that no longer need it.

-Chris


Top
   
 Post subject:
PostPosted: Tue Apr 27, 2004 6:07 pm 
Offline
Senior Newbie

Joined: Sat Mar 13, 2004 7:18 am
Posts: 8
(edit: incorrect explanation deleted)Wow, thanks for your fast reponse, Chris!(/edit)

Quote:
Dropping all of ICMP is a bad thing. Where people get this crazy notion is beyond me. (There is some good ICMP out there!). However dropping just ping is another story.


As I understand it, I had the firewall set up to allow any ICMP related to an already existing connection or any ICMP I sent. Would this let through all the 'good' ICMP while blocking the 'bad' ICMP?

My understanding was that ICMP is bad b/c it can be used to determine the version of linux you're running...but maybe that is just heresay?

Quote:
(Some what related/unrelated note: The more you attempt to drop (aka "blackhole"), the more you look like you have something to hide


Do you think it would be better to set the default policy to reject instead of drop?

Thanks,
-Mike


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group