Ok to let all ICMP traffic through firewall?

Sep 23, 2005 123 Replies

ISP interruptions of service, probably nothing whatsoever to do with ICMP.

and I would be suprised if there is that link you say. That when the windows firewall is on you have problems.

you could try turning the windows firewall off, see if you still have problems. but that can possibly be a bit of a security hazard. You could try a different personal firewall. or shutdown any windows services listening on 0.0.0.0 (netstat -an will list services).

Actually, if you're behind a home router, you can turn off the windows firewall and you'll certainly be fine.

do start..run..cmd and type ipconfig, and see what ip address it gives you. If it's like 192.168.0.1 then you're behind a home router. so it's not so bad to turn off the windows firewall.

I think your diagnosis that the windows firewall being on causes problems, might be a misdiagnosis. Maybe your ISP is just bad.

Key test of your diagnosis is to try without the windows firewall.

Your diagnosis isn't really a diagnosis because you just think you've foudn a link between one thing and another thing (wuindows firewall adn interruptions). you havent' really tested it(tried running without the windows firewall). And you know of no reason (ICMP theory is not it), why the windows firewall being on would cause interruption problems.

Bad Firewall settings don't cause interruption problems. THey either block or allow. no temperamental behaviour there. And Firewalls that don't work don't disconnect you, especially not temperamentally.

Do you have a router? may be it's faulty. It could be the router is bad. Though usuaslly rouetrs have to be turned off and on to fix their temperamental problems. If you just get an interruption temporarily, that is starnge. Maybe you should investigate what you mean by an interruption, whether you're completely knocked off the internet, whether you have an ip from your 'home router'. e.t.c. what the symprtoms of the interruption are.

Thank you for the additional information. My problem is now, that I face during an evening several interruptings of my connection to the internet. These problems began, I think, when I switched on the XP fire wall. So I assumed, that my provider send messages like a ping to see, if my pc is still on line. So I switched nearly all ICMP options on, but it didn'd help. The following icmp-options are marked now as accepted:

- Eingehende Echoanforderungen zulassen Is it Echo or is it Echo reply ?

- Nicht verfügbares ausgehendes Ziel zulassen Destination unreachable ?

- Ausgehende Zeitüberschreitung zulassen Time exeeded ?

- Ausgehendes Parameterproblem zulassen Parameter Problem ?

My Windows is a german version, so I have only the german texts of the options available, sorry.

Klaas

I don't think so.

It is allowing echo and sending echo reply afterwards.

Yes.

Yes.

Yes.

Yours, VB.

Yes. Before doing this, the OP could use

formatting link
to stop offering services.

Yours, VB.

there are side effects though. I vageuly recall running that, then at one point, trying to start the windwos firewall - expecting the screen to just come up, and it started loading something. It's not really clear, for each service, what that program does to disable it. There are side effects. Many services can be disabled with no side effects, via adminsitrative tools.. So, what other services are there? there can't be many.

Also, I didn't notice a restore option in that program at the time I used it.

Say I were to manally disable the messenger service, and UPnP, and disable file and print sharing (port 139), and what other services are there? lsitening on 0.0.0.0 I guess there's NBTSTAT maybe(135) but I don't know how to disable that noe. it'd be beter to turn these off manually if possible. Or for the program to say exactly how it has disabled the service, and what side effects there are.

There can onyl be a handful of services that cannot be easily disabled manually. No reason for a whole program to do them and not list details or even services running that it is disabling.

I think it's better for the user to just be educated on what services cannot be turned off manually, and they just run a script that does some registry hacks and warns of te side efects.

Steve gibson wonud me up with his "shoot the messenger" and his program to disable plug and play. When thesecan be easily disabled in windows. How many servies are left that windows runs and cannot be disabled easily?!

Disagree. A lot depends on your threat model - what are you doing, and what are you trying to protect against. Where I work, types 8 in and 0 out are not allowed at the perimeter and neither 0 or 8 are allowed through the internal routers (though all hosts on a given sub-net can ping and will respond to pings). Only a limited number of codes (below) of type 3 are allowed. My home LAN is set up in similar fashion. But what works for me may not be what you need or desire, and vice-versa.

Two minor nits - "UNIX" is a registered trademark of The Open Group. "iptables" is the current user interface to the netfilter firewall that is part of the Linux kernel. Two other older interfaces (ipfwadm and IPCHAINS) also exist and are occasionally used, but Linux is (and the various BSDs are) often described as "UNIX like" or (incorrectly) "UNIX clones" but are not licensed to use the tradename UNIX to describe the O/S. Other O/S such as the BSDs and the several registered UNIX operating systems have firewalls, but don't use 'iptables'.

The 'code' is a sub part of the type - and varies between the various types. Code 1 in type 3 has nothing to do with code 1 in type 11. You should also note that firewall logs often lists the 'Type' number in the spot where TCP and UDP would list the 'source' port number (ICMP does not have ports), and the 'Code' number where the 'destination' port number would be listed. This is done only because they don't bother changing the log headings. It's a logging function only, and has no effect on operation.

Those are six of the 16 defined codes applicable to Type 3 (Destination Unreachable).

That's 11 of the 27 defined types. RFC0792 describes ICMP, but a number of other documents had added more types and codes in the 24 years since RFC0792 was written. See

formatting link
Old guy

then they are closed. the port is 100% secure. No server application is listening there. Nothing to be exploited

if all ports are closed. you have no ports so nothing that that needs protecting. But you could use a firewall anyway just incase you do decide to start a service, or you inadvertently start one.

- I ran in parallel TCPview, so I knew, what ports had been open

that is good.

Many posts have dealt with this issue. Gibson is a liar, his philosophy is to spread disinformation, obfuscate technical knowledge. This way he protects the wider community by keeping everybody ignorant. He also likes to keep people dependent on him. Look carefully at his site and you'll see it's written by a marketter. Steve Gibson is a marketter. He knows his stuff and is intentionally lying. He has admitted to spreading a disinformation campaign (his own words). There is an audio file online with him admitting it

formatting link
Calls packets 'nanoprobes', just obfuscating everything. Pretends he's invented new technologies.

45:15 (minutes:seconds) "I set up a deliberate disinformation campaign from the beginning"
formatting link
(see 45:15 into that file)

They can't. So it's safe.

To my limited knowledge, Stealth just means that the port doesn't respond to say that it is closed. Yet it'd do no ahrm if it did. Stealth doesn't hide the comp at all. IP is still there. try

formatting link

If it were listening on 0.0.0.0 then it'd be a problem. But fortunately you're misreading it. In the remote port column, the 0.0.0.0 just means that nobody is connected to it. It's not listening on 0.0.0.0 In the local column, 0.0.0.0 would mean anybody can connect. The windows firewall alg.exe - see the local column is listening on

127.0.0.1, which I don't fully understand, but it sort of means that only your computer can connect to it. And that connection won't even pass through your NIC. It's called a loopback address. So that's safe. As would be an address like 192.168.0.1 'cos that means that the connection is open to any other comp on your LAN(would of course pass through NIC). For you who doesn't want any services open to the public, 0.0.0.0 in the local column is a problem / issue.

well, even with no services running. If a website exploits your web browser installs something, it can make an outgoing connection, and treansfer data out. And all that time you won't have been running any services. Safer to not use IE. Fortunately, most of these progs are jst stupid advertising things. But if you have a real reason to be worried of being targetted by a professional, then , safest thing to do is to keep any important data stored ona computer that doesn't have an internet connection. I don't really knwo much about securing myself from a serious hacker!

faulty DSL modem? faulty ISP? it's easier to change modem than change isp. So consider exploring that possibility.

Are you suer you're not behind a router? Either way, doesn't matter. The router or modem or router/modem, may be faulty.

It's hard to have DSL and not be behind a router. The only way I know of is to use a PCI DSL Modem card. All the so-called DSL modems I see are 'home routers' .

Google your ISP . [insert ISP name]+crap. I did that, searched in usenet and the web and foudn out what ISPs to avoid. OFten when ppl complain about an ISP they lso post a better one.

Many UK ppl wrote of moving from the hell of demon internet, to the peace of Zen. some ISPs have a bad reputation of DCing customers from time to time. If you're getting Dced because of the ISP, then it's very likely you'll find 100s of others online with the same experience. Then you'll know.

It's not needed - so why allow it.

If you're using the Windows-Firewall, you don't need this program. Just start it again, and choose the lowest point - afterwards, your system is configured like it was before.

"Shutdown Windows' servers" is shutting down services, too, which are needed by the Windows-Firewall.

If you want to know, what "Shutdown Windows' servers" does exactly, you could read the source code. You can download it at:

formatting link
The program does just the same as Torsten's script in version 2.1, though. So you can download Torsten's script, too, and just read the commands Torsten is executing. They're usual Windows commands, you can enter at the command processor's prompt.

Unfortunately, there are some. Especially, stopping Windows to offer DCE RPC and DCOM over DCE RPC (and SMB name services and so on) at all requires some registry configuration.

I would be happy, if Microsoft could fix that.

Just start it again, and choose the lowest point again (named "unsecure"). This is the restore functionality. The text of this point changes to "restore" ;-)

The latter is done by configuring the registry, together with configuring DCOM and RPC.

Yes.

Yes. Please better use Torsten's script. You can modify and adapt it for your needs. "Shutdown Windows' servers" is there only, because I wanted to offer this possibility for people, too, who don't feel comfortable with black windows and grey text ;-)

For people like you, who are interested in what's goin'on exactly, but perhaps are no C programmers, Torsten's script is the much better choice:

formatting link

Yes. I think so. I'm offering "Shutdown Windows's servers" as an addition to it as "one-click-solution".

Yours, VB.

Moe Trin wrote: [ICMP]

What's your problem with ToS and echo?

Yours, VB.

My ISP promised me to check the isdn-line meanwhile

Life is boring so I take a risk from time to time. I switched my XP fire wall off and did tests against pcflank and shields up. Both sides report, that my pc is visible now and all ports are closed, buth not in stealth mode. No port is reported as open. I should use a fire wall. - I ran in parallel TCPview, so I knew, what ports had been open and I checked these ports again against shields up, but they reported them as 'Closed'.

A report from shields up was: Solicited TCP Packets: RECEIVED (FAILED) - As detailed in the port report below, one or more of your system's ports actively responded to our deliberate attempts to establish a connection. It is generally possible to increase your system's security by hiding it from the probes of potentially hostile hackers.

As I said above, all ports were reported as closed, but not stealth. As I understand it, closed ports shouldn't be a severe risk, didn't they? How can they make a connection via a closed port? Wondering.

The only process listening to 0.0.0.0 was alg.exe and that is the fire wall of XP. For the tests described above I switched it off.

I'm afraid, but I'm not behind a router. For different reasons I have to rely on the pc alone.

My pc gets completely disconnected from the internet from time to time. The only thing I changed was, I started the XP fire wall. So I assumed the XP fire wall might be the reason. But now I had again a disconnected pc without the XP fire wall, so there have to be other reasons.

Klaas

That isn't entirely true. There is still an application which receives the packet and evaluates to it determine how to handle the packet.

It's possible, although relatively unlikely, that there is a bug in the way your TCP stack implements something at the protocol layer which could result in a buffer overrun or something similar.

ah, so the packest don't jut arrive in a buffer for reading by applications. some software passes them to the app?

is this sowftware's function defined by TCP/IP in any RFC?

i'm guessing perhaps there's another piece of software that reaas the TCP port and passes it to the itnerface software you refer to. wouldn't want to shut that one down!

How can you test whether a port is closed, or whether the whole interface is shut down ?

I'd have thought that if the whole interface was shut down, there'd be no response, and thus it'd be reported as stealth by an online scanner. Though no software would be sitting there choosing not to respond.

I will be getting Stevens TCP/IP book when i'm more advanced. Is this topic dealt with in there?

thanks

Oh, yes, it is.

No. There is software, though - and without shutting down the interface, there will remain software which tests this, also with "stealthed" interfaces.

Yours, VB.

I don't set corporate policy - but ping inbound is blocked at the perimeter to prevent system mapping - seems we'd prefer people not to know our layout because they have no demonstatable need for that. Blocking at the internal routers is for the same reason. I don't know about your setup, but our users are not responsible for diagnosing network problems, and very few of them have administrative (root) privileges, so even if they discovered the cause of a problem, they can't do a thing about it - other than pass the word to the hell desk.

Are they having problems? Fine, can they ping the gateway at $BROADCAST-1 or -2? If they can, can they resolve the hostname of something local? The DNS servers are not on each subnet - so resolving says they can get through a router. That being the case, the problem isn't their system, and our NOC people will handle it. As the network is monitored, we may well know about it already anyway. Having at least five neurons, our NOC people know how to use other tools besides ping to evaluate network connectivity. Remember - our users don't have root, so they can't fsck up their own systems, never mind others. They can't install stuff, so that prevents a lot of problems too.

ToS? I can't readily find the document, but we did a study of ICMP types and decided that only types 3 and 11 were needed (we don't run IPv6 yet, and the others are either obsolete, not applicable, or not used). If I recall correctly, we _used_ to allow type 4, but stopped using it after a DOS attack - TCP window size is usually adequate instead. Of the 16 Type 3 codes, only the first five were needed/used. The rules from/to the DMZ are different - and that allows someone from the NOC to work/test from there to diagnose problems to the outside, but that's it. We don't serve ANYTHING to the outside from anywhere other than the DMZ, so that's not a problem either. ALL inbound 113/tcp is redirected to an "ID server" that answers with an encrypted string, so that's neither a problem for our users or a security risk to us.

My home setup is similar - except that I have root on all systems, so I can diagnose and fix problems as needed. Thus far, outbound pings, type 3 codes 0-4 and type 11 has worked without problems. What more do I need? It ain't broke - I don't have to fix it.

Old guy

1122 Requirements for Internet Hosts - Communication Layers. R. Braden, Ed.. October 1989. (Format: TXT=295992 bytes) (Updated by RFC1349) (Also STD0003) (Status: STANDARD) 1123 Requirements for Internet Hosts - Application and Support. R. Braden, Ed.. October 1989. (Format: TXT=245503 bytes) (Updates RFC0822) (Updated by RFC1349, RFC2181) (Also STD0003) (Status: STANDARD)

Assumes the ARP cache on the router has timed out, or if the destination is more than a hop beyond, the routers have talked about it via RIP, BGP, OSPF, or something similar.

Possibly 'TCP/IP Illustrated Volume 1 The Protocols', Addison Wesley

0-201-63346-9 - 576 pgs, US$LOTS, 1994 and 1996 at least. Volume 2 is less common - 0-201-63354-X. It's used as a college textbook primarily, but a lot of network people have a copy, and use it. It's also frequently suggested as a good read - to the extent that I've got the title, publisher, ISBN, and page count memorized. He was actually a very good author.

Old guy

Yes. This is done by the IP stack software in the operating system's kernel.

No. The RFCs mainly are defining protocols and usually not how to implement them.

There are two common ways for a TCP/IP implementation in the wild, though, and most of the operating systems are using one of those two. The first is BSD sockets, the second is called XTI.

With both it is like I described.

Windows uses BSD sockets BTW, Winsocket is a derivate of it. Linux uses a re-implementation of BSD sockets and the BSD socket API. For example, Solaris and HP-UX on the other side use XTI. But both are offering a BSD socket API today.

formatting link
formatting link

According to the protocol, sending SYN to a TCP port which is closed requires sending either TCP RST back, or sending ICMP port unreachable.

Sending anything to an interface, which is down, does not provoke an answer from this interface. Instead, one gets an ICMP host not found or an ICMP network not found from a router before the host.

No. You will get a "this host does not exist", if the scanner works.

Yes, of course it is, if you mean "UNIX Network Programming".

Yours, VB.

^^^^^^ ^^^^^^^

[RFC 1122, 1123]

I've underlined the most important words ;-)

[Richard Stevens]

Yes. An excellent author.

Yours, VB.

I understand ;-)

Yes.

ACK.

Yours, VB.

Thank you for explaining these details.

The only adress I use IE for is the MS update page for Windows. For all other adresses I use a different browser.

Thank you for advice. I'll do that the next days.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required