IEWB - RS -Lab 2 Task 9.4 - ICMP filtering

From: Adhu Ajit (adhu_ajit@yahoo.com)
Date: Tue Nov 14 2006 - 19:01:07 ART


The solution for this question was a bit different from what I thought would be the solution.
   
  I dont quite understand why the two lines:
   
  permit icmp any any time-exceeded
  permit icmp any any port-unreachable
   
  have been inserted before the line:
   
  evaluate ICMP
   
  Should'nt "evaluate ICMP" statement take care of all ICMP responses coming back due to traffic orignated form the inside network ?
   
  Anyone care to comment ?
   
  Thanks in advance.
   

 
---------------------------------
Everyone is raving about the all-new Yahoo! Mail beta.



This archive was generated by hypermail 2.1.4 : Fri Dec 01 2006 - 08:05:47 ART