ipfw And ping

Tim Daneliuk tundra at tundraware.com
Fri Dec 2 02:58:00 UTC 2011

On 12/01/2011 08:56 PM, Robert Bonomi wrote:

> Similarly, I let the firewall respond to pings adressed to it's _external_
> interface, but silently drop anything addressed any further inside my
> network.  (If they can _reach_ my firewall, then a problem, whatever it
> is, *is* 'my problem' and that's all anybody on the outside needs to know,
> or to tell me, if reporting a problem. :)

I NAT behind the FW so they're not getting anywhere behind it...

