Help: meaning of ICMP_UNREACH message from firewall

I can't understand what to do about this ICMP message from my Filseclab software firewall:

Application: SYSTEM Direction: In Remote IP: rz.vrx.net Status/Bytes: RECV/70 Description: ICMP_UNREACH[ICMP_UNREACH_PORT](bad port)|RT:9|

Presumably this has something to do with an ICMP packet not being able to reach some port on my system. Can someone explain this a bit more please.

And importantly, what can I do on Filseclab to overcome this?

If I turn my firewall OFF then DNS lookups seem to happen faster and some (but not all) of the Usenet servers I belong to work faster. I suspect that these trapped ICMP messages might have something to do with the slowness I am getting.

Reply to
Zak
Loading thread data ...

You could read RFC792 / Internet Standard 0005.

You don't need this information at all. It is ridiculous, that your "Personal Firewall" is bothering you with such things.

Then you have your solution already.

Yours, VB.

Reply to
Volker Birk

Don't have a clue what Fileseclab even is, but the problem seems pretty straight forward. Someone's blindly rejecting echo requests (pings) and your software expects them. The "RT:9" suggests that the responding machine is sending "Administratively Prohibited" type replies to pings, which generally means some firewall not in "stealth" mode.

I think you answered your own question. Reconfigure your firewall to properly respond to or pass echo requests if that's what all the evidence tells you to do.

Reply to
George Orwell

Not quite. What happened is that something on your machine tried to open a connection to some remote system, and that one answered with a "port unreachable" - nothing listening on the port or the port us blocked (filtered). This is part of the normal (presumably TCP) negotiation.

Try looking up the ICMP types and decide which ones you want to allow in (hint: a lot of them are undesirable, but this is not one of them).

Reply to
Mailman

This particular firewall does not permit me to choose which type of ICMP it passes or rejects. So to avoid problems I set it to pass all ICMP traffic.

But I stil get that wierd message. If I close the firewall down completely then the app seems to communicate ok. Does this help anyone to know what might be happening?

Reply to
Zak

Perhaps you could consider another filtering software.

Yours, VB.

Reply to
Volker Birk

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.