From owner-freebsd-questions Wed May 27 08:32:10 1998 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id IAA21199 for freebsd-questions-outgoing; Wed, 27 May 1998 08:32:10 -0700 (PDT) (envelope-from owner-freebsd-questions@FreeBSD.ORG) Received: from implode.root.com (implode.root.com [198.145.90.17]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id IAA21142 for ; Wed, 27 May 1998 08:31:54 -0700 (PDT) (envelope-from root@implode.root.com) Received: from implode.root.com (localhost [127.0.0.1]) by implode.root.com (8.8.5/8.8.5) with ESMTP id IAA07635; Wed, 27 May 1998 08:32:03 -0700 (PDT) Message-Id: <199805271532.IAA07635@implode.root.com> To: William Woods cc: FreeBSD Questions Subject: Re: firewall question... In-reply-to: Your message of "Tue, 26 May 1998 19:01:49 PDT." <356B740D.7A54CCBE@cybcon.com> From: David Greenman Reply-To: dg@root.com Date: Wed, 27 May 1998 08:32:03 -0700 Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG >What would be the firewall rule to stop all incomming ICMP packets from >all? You don't want to stop ICMP UNREACH_NEEDFRAG packets else you'll break Path MTU Discovery which will cause problems when connecting to some hosts. -DG David Greenman Co-founder/Principal Architect, The FreeBSD Project To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message