Re: Problem of blocking ICMP packets
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Problem of blocking ICMP packets



On Wed, 16 Jun 2004 11:00:29 PDT, Sally Floyd said:

> to the browser.  Presumeably if the web server wanted to use something
> like QuickStart, it could have the firewall configured to allow the
> IP QuickStart Option not to be blocked on the outgoing SYN packet?

Given the number of times we've had IWF reports that basically boil
down to 'ntp-[12].vt.edu is probing me from port 123", and even more
interestingly the number of times we've been asked by the remote user
why their machine is trying to contact ntp-1.vt.edu, I have to classify
the concept that "People will remember to put appropriate punchouts
in their firewall when they deploy a service" as "wishful thinking".

Attachment: pgp50PPr5bWAk.pgp
Description: PGP signature

_______________________________________________
Ietf mailing list
Ietf at ietf.org
https://www1.ietf.org/mailman/listinfo/ietf

Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.