Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Allow Traceroutes Out to internet, no Pings/traces in. On Both PIX and 2610

Reply
Thread Tools

Allow Traceroutes Out to internet, no Pings/traces in. On Both PIX and 2610

 
 
Scott Townsend
Guest
Posts: n/a
 
      10-07-2004
We were getting hit with the Viruses that used PING to see if anybody
was home so I removed all ability to Ping/Traceroute in or our of our
network at both the Edge Router and the Firewall.

It is now getting to be a pain to not beable to ping/traceroute to
some hosts on the internet.

I'd like to set it up so I can Ping or traceroute from behind the Edge
router and the PIX from specific subnets, but not let anyone
ping/traceroute to us.

What is the best way to set this up on both the PIX and the 2610 (IOS
12.3(6a))


Thanks,
Scott<-
 
Reply With Quote
 
 
 
 
Ben
Guest
Posts: n/a
 
      10-08-2004
Too easy, just allow echo requests out and echo replies in but not visa
versa.
You can specify the ICMP message type in an access-list.

"Scott Townsend" <> wrote in message
news: m...
> We were getting hit with the Viruses that used PING to see if anybody
> was home so I removed all ability to Ping/Traceroute in or our of our
> network at both the Edge Router and the Firewall.
>
> It is now getting to be a pain to not beable to ping/traceroute to
> some hosts on the internet.
>
> I'd like to set it up so I can Ping or traceroute from behind the Edge
> router and the PIX from specific subnets, but not let anyone
> ping/traceroute to us.
>
> What is the best way to set this up on both the PIX and the 2610 (IOS
> 12.3(6a))
>
>
> Thanks,
> Scott<-



 
Reply With Quote
 
 
 
 
Rod Dorman
Guest
Posts: n/a
 
      10-08-2004
In article <> ,
Scott Townsend <> wrote:
> ...
>I'd like to set it up so I can Ping or traceroute from behind the Edge
>router and the PIX from specific subnets, but not let anyone
>ping/traceroute to us.


Keep in mind that if everyone adopted this philosophy it would
effectively remove ping and traceroute as usefull diagnostic tools.

--
-- Rod --
rodd(at)polylogics(dot)com
 
Reply With Quote
 
Javier Henderson
Guest
Posts: n/a
 
      10-08-2004
(Rod Dorman) writes:

>
> In article <> ,
> Scott Townsend <> wrote:
> > ...
> >I'd like to set it up so I can Ping or traceroute from behind the Edge
> >router and the PIX from specific subnets, but not let anyone
> >ping/traceroute to us.

>
> Keep in mind that if everyone adopted this philosophy it would
> effectively remove ping and traceroute as usefull diagnostic tools.


Also, ruthless blocking of ICMP messages breaks PMTUD, which is
a Bad Thing.

-jav
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Boot ROM chip required to upgrade both a Cisco 2610 and a Cisco 2620 router to support 32 megs+ flash and more than 64 megs RAM Mike Rahl Cisco 1 06-14-2007 05:33 PM
Worth the Effort? Internet > uBR > 2610 > PIX > DMZ and Inside Network seaneboyee@gmail.com Cisco 0 04-12-2007 11:45 PM
PIX 501 - allow icmp out but deny everything else out nicough@gmail.com Cisco 2 11-18-2006 03:44 PM
Secure Pix 506 Firewall/Cisco 2610 Router VPN? Kevin Cisco 2 05-03-2004 12:15 AM
connecting a Cisco 2610 to a Cisco PIX Firewall paul Cisco 1 11-10-2003 04:48 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57