> Don't filter out all ICMP; you'll break things in sometimes subtle
> ways. If you want to break traceroute, do so without breaking path
> MTU discovery, port unreachable, &c.
Seconded. We tried blocking all ICMP to our mainframe net once (back in
the "ping of death" days) and inadvertently broke ccMail. For some inane
reason, it makes sure it can ping an SMTP server before attempting the
TCP connection to send mail. Go figure.
/cvk
This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:13:15 EDT