Re: Will an PIX Accept and act on ICMP redirects?

From: Dan Pontrelli (dp595@xxxxxxxxxxxxx)
Date: Sun Jul 29 2001 - 02:14:13 GMT-3


   
> >However why do you want to rely on redirect. Use HSRP on
> >routers and pick up the active router. Have one more link between
> >routers so if better path is with other router, router will forward
> >packet to other router instead of doing redirect.
>
> Excellent point, and is in fact the very point of our argument.
>
> The "need" for an inter-router link is greater if the PIX will not accept
an
> ICMP redirect from the primary router (in this case the HSRP winner) to
the
> other router.

Enabling HSRP on the interface of the router automatically disables ICMP
redirect, so no redirects will be sent to the PIX anyway.
It seems this is no longer true on IOS 12.2 though, as I just tested it out
by enabling HSRP and redirects remained enabled.

-Dan

>
> The answer being put in place IS in fact an inter-router link as we
consider
> this a best practice anyway, but I like to back up my designs with facts,
> hence the request for proof.
>
> Thanks,
>
> Gary A. Donahue
> Alliant Technologies
> Phone: 973-267-5236 Fax: 973-267-5237
> gdonahue@allianttech.com
> **Please read:http://www.groupstudy.com/list/posting.html
**Please read:http://www.groupstudy.com/list/posting.html



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 10:31:44 GMT-3