Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 17 Jul 2001 13:45:32 -0300 (ART)
From:      Fernando Gleiser <fgleiser@cactus.fi.uba.ar>
To:        Mark <mlivingstone@ottawa.com>
Cc:        <freebsd-questions@FreeBSD.ORG>
Subject:   Re: how could this PACKET get through?!
Message-ID:  <20010717134041.G96585-100000@cactus.fi.uba.ar>
In-Reply-To: <20010717120556.A28512@tmd.df.ru>

next in thread | previous in thread | raw e-mail | index | archive | help
Without knowing your firewall rules it is difficult to tell, but a good
guess is you are keeping state on the outgoing connections and the icmp
packet was in response to one of those outgoing connections.


			Fer


On Tue, 17 Jul 2001, Mark wrote:

> Re,
>
> I am blocking most incoming icmp traffic:
>
> icmp-type 0
> icmp-type unreach code 3
> icmp-type unreach code 4
> icmp-type timex
>
> also.. im running jail, but icmp doesn't work from there.. how could this packet get through my firewall:
>
> Jul 17 05:12:53 ml ipmon[18381]: 05:12:52.177910 2x ed0 @0:35 p 0.so-3-0-0.XR1.ATL1.ALTER.NET -> jail PR icmp len 20
> 56 icmp 11/0 for jail,3366 - 63.108.161.50,1439 PR tcp len 20 40 IN
>
> Please, reply by e-mail.
>
> thanks in advance!
>
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-questions" in the body of the message
>


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010717134041.G96585-100000>