Author Topic: Firewall question  (Read 1854 times)

0 Members and 1 Guest are viewing this topic.

Offline Free Vulcan

  • Technical
  • *****
  • Posts: 23,756
  • Gender: Male
  • Ah, the air is so much fresher here...
Firewall question
« on: April 30, 2017, 08:49:19 pm »
Question for the techies. My firewall is getting knocked on pretty hard, so hard it often bounces me off line. The log indicates it's all from ingoing and outgoing ICMP. Tracked some of the remote IP's and a number go to suspicious places like Russia, Romania, and Ukraine.

I've disabled the ICMP permissions for now, wonder if you could give me a heads up as to what may be going on.

@Oceander
The Republic is lost.

Offline InHeavenThereIsNoBeer

  • Hero Member
  • *****
  • Posts: 4,127
Re: Firewall question
« Reply #1 on: April 30, 2017, 09:20:57 pm »
ICMP flood (or ping flood).

Someone is either trying to learn more about your network, or disrupt your service with a denial of service attack. 

There's probably not a lot of downside to disabling ICMP replies in a home or small office environment.  Not everyone agrees, but I prefer to drop requests vs rejecting them in case of a DoS.

You may want to contact your ISP, as their hardware should be able to filter out a lot more than yours without falling over.

Here's more detail than you probably want:

https://www.sans.org/reading-room/whitepapers/threats/icmp-attacks-illustrated-477
My avatar shows the national debt in stacks of $100 bills.  If you look very closely under the crane you can see the Statue of Liberty.

Offline Free Vulcan

  • Technical
  • *****
  • Posts: 23,756
  • Gender: Male
  • Ah, the air is so much fresher here...
Re: Firewall question
« Reply #2 on: April 30, 2017, 09:43:45 pm »
ICMP flood (or ping flood).

Someone is either trying to learn more about your network, or disrupt your service with a denial of service attack. 

There's probably not a lot of downside to disabling ICMP replies in a home or small office environment.  Not everyone agrees, but I prefer to drop requests vs rejecting them in case of a DoS.

You may want to contact your ISP, as their hardware should be able to filter out a lot more than yours without falling over.

Here's more detail than you probably want:

https://www.sans.org/reading-room/whitepapers/threats/icmp-attacks-illustrated-477

Thanks, informative article. No problems so far shutting them off, so I'm going to run with it and let my ISP know what's going on.
The Republic is lost.

Offline ShadowAce

  • Hero Member
  • *****
  • Posts: 157
Re: Firewall question
« Reply #3 on: May 11, 2017, 01:52:31 pm »
@Free Vulcan

Try this article about a Firewall/IDS system.  It's free and seems to work pretty well:

CSF/IFD