Some operating systems have different default ping or echo packet sizes.
In Solaris, the default icmp size for ping is 56 bytes.  I've noticed 32
bytes in Windows and 72 bytes on cisco routers.  You can always change the
size at the command line when you issue the command.


Nathan

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
Sent: Wednesday, June 02, 2004 11:52 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Echo request too long

Steve,

Thanks for the quick reply.   Indeed it was SmartDefense but what puzzled
me was that not all pings were dropped with Echo request too long message.
Some went through fine (to the same external host).

Regards,

Huiqi Liu
Veritas DGC Limited



                      Steve Baker <[EMAIL PROTECTED]>
                      Sent by: Mailing list for                 To:
[EMAIL PROTECTED]
                      discussion of Firewall-1                  cc:
                      <[EMAIL PROTECTED]         Subject: Re:
[FW-1] Echo request too long
                      KPOINT.COM>


                      02/06/2004 16:24
                      Please respond to Mailing list
                      for discussion of Firewall-1






Most likely, these are being generated by SmartDefense if you enabled max
ping size under IP and ICMP options. The default value for this is 64 bytes
and the default action is log.

I would not change the max ping size to anything larger than 64 bytes unless
you're seeing some sort of problem with an application that is using icmp
(and then I'd probably blame the application ;)) . You could certainly set
the tracking to none if you're not concerned with them, but honestly, if
you're getting enough of them that they are impacting the effectivness of
your logs you probably want to try and figure out where they are coming from
and take appropriate action.

-Steve


> Dear All
>
> I'm sure I have seen this posted already but can't find anything at
> the moment.  And it might be something I should know about already:
> but what does "Attack info: Echo request too long" in the logs?  And
> how to stop them?
>
> Thanks,
>
> Huiqi Liu
> Veritas DGC Limited
>
> =================================================
> To set vacation, Out-Of-Office, or away messages, send an email to
> [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list, please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your subscription options,
> email [EMAIL PROTECTED]
> =================================================

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to