RE: icmp filtering

From: Richard Dumoulin (richard.dumoulin@vanco.es)
Date: Tue Jun 08 2004 - 18:46:15 GMT-3


It allows all icmp including ping's !!

Do "permit icmp any any ?" and you'll see the options,

--Richard

-----Original Message-----
From: ccie2be [mailto:ccie2be@nyc.rr.com]
Sent: martes, 08 de junio de 2004 23:40
To: Group Study
Subject: icmp filtering

Hi guys,

I hope this isn't too dumb a question, but...

Can someone confirm what this acl entry does?

ip access-list ext ping
permit (or deny) icmp any any <-----

In particular, does this allow all icmp message types or just echo-request
and echo-reply?

I've search the Doc Cd and the whole of cisco.com but couldn't find anything
definative.

I would think it would allow ( or deny) all icmp message types but, I'm
doing practice IE lab 2, task 10.8 - 10.10 and the solution seems to
indicate that it only permits message types echo-request and echo-reply.

Any feedback would be appreciated. Also, if someone knows of any links
which discusses in detail, please let me know.

TIA, Tim



This archive was generated by hypermail 2.1.4 : Sat Jul 03 2004 - 19:40:35 GMT-3