21 Apr
2013
21 Apr
'13
17:37
Togan Muftuoglu wrote:
On 04/21/2013 05:43 PM, Cristian Rodríguez wrote:
Yes, also the following icmp types must never be blocked, if SUSEfirewall does not implicitely creates rules always allowing them, then it is absolutely retarded and you should not use it. In SuSEfirewall2 safe_icmp_replies and safe_icmp_replies6 defines what are allowed
- icmp fragmentation-needed That one is missing
- icmp time-exceeded It is there
Carlos, maybe better to bugzilla the icmp fragmentation-needed
Hmmm.... I just checked my 11.4 firewall and none of that is there. -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org