login
Header Space

 
 

Re: Prevent circumventing dansguardian with pf

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Thursday, April 26, 2007 - 1:43 am

Tobias Weingartner wrote:

As very often in this world, none of these points of view is absolutely
perfect in all situations.

Regarding violation of RFCs, I found RFC 1812, which states that routers
have to implement echo replies, but one should be able to switch them off:


RFC 1812 "Requirements for IP Version 4 Routers", page 57/58:

4.3.3.6 Echo Request/Reply

    A router MUST implement an ICMP Echo server function that receives
    Echo Requests sent to the router, and sends corresponding Echo
    Replies.  A router MUST be prepared to receive, reassemble and echo
    an ICMP Echo Request datagram at least as the maximum of 576 and the
    MTUs of all the connected networks.

    The Echo server function MAY choose not to respond to ICMP echo
    requests addressed to IP broadcast or IP multicast addresses.

    A router SHOULD have a configuration option that, if enabled, causes
    the router to silently ignore all ICMP echo requests; if provided,
    this option MUST default to allowing responses.


Andreas
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Prevent circumventing dansguardian with pf, Tobias Weingartner, (Wed Apr 25, 4:19 pm)
Re: Prevent circumventing dansguardian with pf, Andreas Kaeser, (Thu Apr 26, 1:43 am)
Re: Prevent circumventing dansguardian with pf, Chad M Stewart, (Wed Apr 25, 4:43 pm)
Re: Prevent circumventing dansguardian with pf , Tobias Weingartner, (Wed Apr 25, 8:31 pm)
Re: Prevent circumventing dansguardian with pf, Jason Dixon, (Wed Apr 25, 8:48 pm)
Re: Prevent circumventing dansguardian with pf, J.C. Roberts, (Wed Apr 25, 11:01 pm)
Re: Prevent circumventing dansguardian with pf, Mathieu Sauve-Frankel, (Wed Apr 25, 7:02 pm)
Re: Prevent circumventing dansguardian with pf, Stuart Henderson, (Wed Apr 25, 7:16 pm)
Re: Prevent circumventing dansguardian with pf, Timo Schoeler, (Wed Apr 25, 4:40 pm)
Re: Prevent circumventing dansguardian with pf , Tobias Weingartner, (Wed Apr 25, 6:29 pm)
Re: Prevent circumventing dansguardian with pf, Timo Schoeler, (Thu Apr 26, 3:12 am)
Re: Prevent circumventing dansguardian with pf, Joachim Schipper, (Wed Apr 25, 5:56 pm)
Re: Prevent circumventing dansguardian with pf, Timo Schoeler, (Wed Apr 25, 6:08 pm)
speck-geostationary