Re: icmp packets - disabling via sysctl, or cisco switch ... ?

2006-07-28 Thread Nikos Vassiliadis
On Friday 28 July 2006 06:15, User Freebsd wrote: Two part question here ... first part ... is there a way of just disabling icmp by setting a sysctl, so that a server just doesn't respond to them? No. You can do this using the firewall of your choice ipfw example ipfw add deny icmp from any

Re: icmp packets - disabling via sysctl, or cisco switch ... ?

2006-07-28 Thread Nikos Vassiliadis
On Friday 28 July 2006 06:26, User Freebsd wrote: Just an appendum, but this is what I'm seeing in /var/log/messages right now: Jul 28 00:22:37 io kernel: Limiting icmp unreach response from 6255 to 200 packets/sec Jul 28 00:22:38 io kernel: Limiting icmp unreach response from 6515 to 200

Re: icmp packets - disabling via sysctl, or cisco switch ... ?

2006-07-28 Thread Bill Moran
User Freebsd wrote: Two part question here ... first part ... is there a way of just disabling icmp by setting a sysctl, so that a server just doesn't respond to them? second part ... is there a way of telling a cisco switch to drop all icmp packets, preferrably to all but an exception

Re: icmp packets - disabling via sysctl, or cisco switch ... ?

2006-07-28 Thread Chuck Swiger
Bill Moran wrote: User Freebsd wrote: Two part question here ... first part ... is there a way of just disabling icmp by setting a sysctl, so that a server just doesn't respond to them? second part ... is there a way of telling a cisco switch to drop all icmp packets, preferrably to all

icmp packets - disabling via sysctl, or cisco switch ... ?

2006-07-27 Thread User Freebsd
Two part question here ... first part ... is there a way of just disabling icmp by setting a sysctl, so that a server just doesn't respond to them? second part ... is there a way of telling a cisco switch to drop all icmp packets, preferrably to all but an exception list, but to everywhere

Re: icmp packets - disabling via sysctl, or cisco switch ... ?

2006-07-27 Thread User Freebsd
Just an appendum, but this is what I'm seeing in /var/log/messages right now: Jul 28 00:22:37 io kernel: Limiting icmp unreach response from 6255 to 200 packets/sec Jul 28 00:22:38 io kernel: Limiting icmp unreach response from 6515 to 200 packets/sec Jul 28 00:22:39 io kernel: Limiting