[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Sheflug] Re: Network Goes on Holiday
> blocking all ICMP can be a bad thing as it can potentially mean packets get
> lost, dropped, or corrupted due to router config ... hint: don't block ICMP -
> Destination Unreachable :)
>
> If anyone wants to read the complete blurb, let me know and I'll go and dig
> it out ... :)
>
"sod it" thought I ... I dug it out anyhow :)
http://kt.linuxcare.com/kernel-traffic/kt20000501_65.epl#10
"The web sites are probably behind a firewall which is filtering all ICMP
packets (since some dumb firewall administrator read somewhere that all
ICMP packets are evil). Somewhere in the network path between you and
the web site, there's a link which has a maximum MTU which is smaller
than the ethernet default of 1500 bytes."
And it goes on to give a detail of what's going on to break the remote web
site :) Not a linux problem - its a remote firewall problem. :) Take a read
-- anyone who does network/firewall admin may find it useful :)
Chris...
--
@}-,'-------------------------------------------------- Chris Johnson --'-{ [at]
/ "(it is) crucial that we learn the difference / sixie [at] nccnet.co.uk \
/ between Sex and Gender. Therein lies the key / \
/ to our freedom" -- LB / www.nccnet.co.uk/~sixie \
---------------------------------------------------------------------
Sheffield Linux User's Group - http://www.sheflug.co.uk
To unsubscribe from this list send mail to
- <sheflug-request [at] vuw.ac.nz> - with the word
"unsubscribe" in the body of the message.
GNU the choice of a complete generation.