Re: Disable send ICMP redirect?



On 28 Jun 2006, in the Usenet newsgroup comp.os.linux.networking, in article
<1151525156.121357.266510@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>, bota.florin@xxxxxxxxx
wrote:

It acts as a firewall connecting the local net to different remote
networks (uses for that a separate network interface and connects through
4 different cisco routers) and should forward all Internet traffic to a
router connected to internet (which is on the same local network - both
router and firewall use 192.168.10.0/24 class addresses, the hosts have
addresses from the same class).

Your description is not that clear. Does the router configuration look
like this (use a fixed font in your browser)

---------------------
hosts ------|eth0 Linux box eth1|-----router to world
192.168.10.x | | 192.168.10.y
| eth2|--- some other router
| | 10.10.10.x
| eth3|--- yet another router
--------------------- 172.16.16.x

or are the hosts and router to the world connected to the _same_ network
card like this

---------------------
hosts ------|eth0 Linux box eth1|----- some other router
| | | 10.10.10.x
router --- | eth2|--- yet another router
--------------------- 172.16.16.x

It forwards correctly traffic to the remote networks, but for the
Internet traffic it answers by sending an ICMP redirect, which is conform
to the standard.

This should happen in the second diagram - traffic comes in on eth0, and
is being sent onwards through the same eth0. This is a terrible design
for a network firewall. I think we need to see the routing table.

There could also be confusing in the top diagram (where only the router
is on eth1, and the hosts are on eth0) if you have identical network routes
on eth0 and eth1. If the same address range is used on both interfaces, the
router interface need to be a 'host' route rather than a network route.

Is it possible to disable the sending of ICMP redirect and linux
forward the packets to the correct router (even if the host and the
router are on the same network)? I know this will efectivelly increase
the traffic but it will allow the firewall to correctlly check the
packets.

This really sounds like the hosts and router are on the same wire, which
makes the firewall nearly useless. The firewall must stand between the
two, and this can only be done by having the router on a different NIC
than the hosts.

Old guy
.



Relevant Pages

  • Re: share my printer between 2 computers and surf with 2 computers at same time
    ... The main choice you have to make is whether to have the router include wireless capability or not. ... Because wireless routers for home use are relatively inexpensive these days, I'd suggest buying a wireless router even if you don't initially intend to use that capability. ... If you already have a UTP cable going between upstairs and downstairs, you can use that to have a wired network. ... caused by 1) a misconfigured firewall; ...
    (microsoft.public.windowsxp.network_web)
  • Re: share my printer between 2 computers and surf with 2 computers at same time
    ... The main piece of hardware you need to buy is a router. ... Because wireless routers for home use are ... you can use that to have a wired network. ... caused by 1) a misconfigured firewall; ...
    (microsoft.public.windowsxp.network_web)
  • RE: [Full-Disclosure] Re: January 15 is Personal Firewall Day, help the cause
    ... the>outside world which are in response to packets originating from ... to drop in a little Trojan, your whole network can be compromised. ... NAT router works at Layer 3. ... You still need a personal firewall or ...
    (Full-Disclosure)
  • Re: MSN WORKGROUP
    ... before my router is excess the folder very quickly suddenly it excess the ... Pls guide me how can i make it again this network. ... xp or firewall., secondly i can not find my wirefall optopn in control panel ... Problems sharing files between computers on a network are generally ...
    (microsoft.public.windowsxp.network_web)
  • ~~~~~~~~~~~~~~ IP ADDRESS ~~~~~~~~~~~~~~
    ... block my ip address vista windows ... change public ip address linksys router ... setting up a network ip address ... warcraft server ip address ...
    (sci.misc)