RE: Blocking Virus ICMP flood

From: Don Bowman (don_at_sandvine.com)
Date: 08/25/03

  • Next message: paradigm_at_ugs.com: "Re: Approved"
    To: 'User Ernie' <ernie@spooky.eis.net.au>, Don Bowman <don@sandvine.com>
    Date: Mon, 25 Aug 2003 09:51:05 -0400
    
    

    > From: User Ernie [mailto:ernie@spooky.eis.net.au]
    > [ Charset ISO-8859-1 unsupported, converting... ]
    > > > From: User Ernie [mailto:ernie@spooky.eis.net.au]
    > > >
    > > > Does anyone know if ipfw can do someting similar to:
    > > >
    > > > deny icmp any any echo tos min-delay
    > > >
    > > > Which is the Cisco command I use to try and limit the flood
    > > > style icmp traffic from the
    > > > recent Internet viruses.
    > > >
    > > > - Ernie.
    > >
    > > ipfw add deny icmp from any to any icmptypes 0,8 iptos lowdelay
    > >
    > I tried that but it gives me the following error:
    >
    > ipfw: unknown or out of order argument `iptos''
    >
    >
    > Does it depend on FreeBSD version? I am running 4.8-STABLE

    I have IPFW2 option enabled, that may be required.
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: paradigm_at_ugs.com: "Re: Approved"

    Relevant Pages

    • ipfw ipf pf etc etc
      ... different firewall/packet filters in FreeBSD 5.3. ... From what I understand there is ipfw pf and maybe others as well? ... To unsubscribe, ...
      (freebsd-newbies)
    • ipfw not working any more after upgrade to 5.3
      ... I just upgraded my FreeBSD box to 5.3-RELEASE-p5 ... ipfw to fwd from one port to another: ... ipfw: getsockopt: Invalid argument ... To unsubscribe, ...
      (freebsd-questions)
    • Re: IpFilter / IpFireWall
      ... except for ones which are related in connections that were established as ... some badly configured servers test for ident (port ... See the security section in the FreeBSD handbook, ... compiling your kernel, and the ipfw manpage, for more details. ...
      (FreeBSD-Security)
    • gigabyte GA-71XE4 (single amd athlon cpu motherboard
      ... freebsd v5.2 and 5.3 boots no problems works well but freebsd v7 locks ... <Parallel port bus> on ppc0 ... unknown: can't assign resources (memory) ...
      (freebsd-questions)
    • FreeBSD Security Advisory: FreeBSD-SA-01:08.ipfw [REVISED]
      ... included in FreeBSD 4.0 and above. ... based on an old version of ipfw and does not contain as many features. ... Due to overloading of the TCP reserved flags field, ... incorrectly treat all TCP packets with the ECE flag set as being part ...
      (FreeBSD-Security)