Hi,
If you set tracking to log, you will see in the Info. column
the icmp-type and the icmp-code, so you
can
translate this and know which kind of ICMP packets are travelling through your
Firewall.
If you want to restrict the type of ICMP packets travelling
through, look at the following services that
are pre-defined in your CP box : echo-reply -
echo-request - dest-unreach -
icmp-proto - info-reply ....
in fact you can select in the services to show only the
ICMP related services.
Met vriendelijke groeten - Bien � vous - Kind regards
Guy ROELANDTS
EMEA GS Internet Expertise
Centre
Compaq Software
Engineer - Belgium
E-mail
: [EMAIL PROTECTED]
Tel: +32(02)729.77.44 (options 3 - 3 -
1)
Fax:
+32(02)729.77.65
-----Original Message-----Hi All,
From: Harshul Nayak [mailto:[EMAIL PROTECTED]]
Sent: Thursday, July 26, 2001 11:14 AM
To: [EMAIL PROTECTED]
Subject: [FW1] FW1 - ICMP handlingIf I am allowing ICMP to flow thru my firewall(FW1) , Can FW1 check the kind of ICMP datagram which is coming thru , and if I want to allow only certain kind of ICMP packets i.e echo request and echo reply and deny all other ICMP datagrams.
Can anyone please guide in setting this rule correctly.
-- ("`-''-/").___..--''"`-._ `6_ 6 ) `-. ( ).`-.__.`) (_Y_.)' ._ ) `._ `. ``-..-' _..`--'_..-_/ /--'_.' ,' (il),-'' (li),' ((!.-'Harshul Nayak - eAlcatraz Consulting(P) Ltd.Chennai, India.
