G
Guest
Guest
Archived from groups: comp.security.firewalls,comp.security.misc (More info?)
In comp.security.misc Dave Dowson <a031003${dd}.nospam@ddka.invalid> wrote:
> On Sat, 24 Sep 2005 02:06:07 GMT, Leythos <void@nowhere.lan> wrote:
> > I already said we allow ICMP with partners and have no problems with
> > VPN's, we do not allow ICMP with the world as a general rule, just with
> > approved partners.
> I still can't understand why you would want to deliberately break a
> valuable feature of IP - and do so in a way such that a user will have
> no idea why their connection to a specific site on the Internet may
> work in some cases but not in others. It's your choice how you
> configure your network, of course, but it seems a rather idiotic
> configuration to me.
Of course, it is.
Yours,
VB.
--
"Es kann nicht sein, dass die Frustrierten in Rom bestimmen, was in
deutschen Schlafzimmern passiert".
Harald Schmidt zum "Weltjugendtag"
In comp.security.misc Dave Dowson <a031003${dd}.nospam@ddka.invalid> wrote:
> On Sat, 24 Sep 2005 02:06:07 GMT, Leythos <void@nowhere.lan> wrote:
> > I already said we allow ICMP with partners and have no problems with
> > VPN's, we do not allow ICMP with the world as a general rule, just with
> > approved partners.
> I still can't understand why you would want to deliberately break a
> valuable feature of IP - and do so in a way such that a user will have
> no idea why their connection to a specific site on the Internet may
> work in some cases but not in others. It's your choice how you
> configure your network, of course, but it seems a rather idiotic
> configuration to me.
Of course, it is.
Yours,
VB.
--
"Es kann nicht sein, dass die Frustrierten in Rom bestimmen, was in
deutschen Schlafzimmern passiert".
Harald Schmidt zum "Weltjugendtag"