Re: firewall, reject: icmp vs. tcp

Jos Vos (jos@xos.nl)
Thu, 11 Apr 1996 13:29:56 +0200 (MET DST)


> > > But shouldn't the ICMP code be one of
> > > 9 Communication with Destination Network is
> > > Administratively Prohibited
> > > 10 Communication with Destination Host is
> > > Administratively Prohibited
> > >
> > > (from RFC1700 Assigned Numbers. These are defined in icmp.h as ICMP_NET_ANO
> > > and ICMP_HOST_ANO respectively.)
> >
> > Quite possibly. They cause bizarre error messages to some people with older
> > hosts, but yes - I'd go with changing to that if someone wants to make the
> > changes, test it and submit a report in a week or so

We should ask ourselves how many percent of the TCP/IP systems in the
world recognizes this code correctly. I understood Windows/NT doesn't
even recognize the other ICMP messages (who was talking about "older
systems"? :-)).

-- 
--    Jos Vos <jos@xos.nl>
--    X/OS Experts in Open Systems BV   |   Phone: +31 20 6938364
--    Amsterdam, The Netherlands        |     Fax: +31 20 6948204