Firewall Working?

BlakkIce

Golden Member
Jun 29, 2001
1,073
0
0
i am used to Zone Alarm Pro and this weekend i switched to a hardware firewall how can i make sure its working (blocking incoming attacks)
 

noninterleaved

Senior member
Mar 25, 2001
628
0
0
The easiest thing to do is run a portscan... dslreports has a java applet that will do it.

Also, if you have IIS running and you have port 80 open on your machine go to c:\winnt\logfiles\....
Somewhere in there (I forget right now) you will find your IIS logs, which will have all requests that have come in.
 

AG73

Senior member
Jan 2, 2001
497
0
0
or have someone ping you. if your firewall is legit, they won't get packets back.
AG
 

TruculentTucan

Senior member
May 6, 2001
680
0
0
<< Your namesake sucks. >>

neither do i.

[edit] HAHAHAHAHAHHHAHAHAHAHHAHAHAHHAHAHAHHAHAHAHAHHAHAHAHAHHAHAHAHAHAHAHHAHAHAHAHAHAH *pauses for breath* HAHAHAHHAHAHAHAHHAHHAHAAH! now i get it. [/edit]
 

sharkeeper

Lifer
Jan 13, 2001
10,886
2
0


<< or have someone ping you. if your firewall is legit, they won't get packets back >>



I see this all the time, Steve Gibson of GRC thinks it's "cool" to be stealth, when in all actuality it's harmful.

This hyper-paranoid approach to security causes some difficulties. For a start, Internet standard RFC 1122 states categorically about ICMP echoes (ping):

3.2.2.6 Echo Request/Reply: Every host MUST implement an ICMP Echo server function that receives Echo Requests and sends corresponding Echo Replies.

Note the MUST rather than SHOULD. This means that any internet user, or ISP server, has a right to expect that all live PCs connected to the internet will respond to ICMP ping requests with an ICMP reply. If a firewall user chooses to stealth ICMP requests so that no response is sent, they have only themselves to blame if they start experiencing problems, because they are in breach of RFC 1122.

The problems that might arise if you kill ICMP responses with stealth are:

Difficulties with DHCP lease acquisition or renewal in cases where the DHCP server checks on the availability of IP addresses, or your presence on the network, with ICMP ping requests [this doesn't actually happen on the original NTL network, but ICMP requests have been seen coming from the DHCP servers of the ex-C&W parts of the network].

Slowness of web connection setup in cases where the remote web server uses ICMP to determine the MTU of the response path.
So you are strongly advised not to apply stealth techniques to the ICMP protocol. In the freeware version of ZoneAlarm, this means you should run it in Medium Security, not High Security, for the Internet Zone. In ZoneAlarm Pro, you can configure ICMP behaviour to permit ICMP echo packets in and out even in High Security, using the Customize button of the Security Settings panel.

Similar problems arise with certain NAT routers, such as the Linksys. By default, the Linksys does not reply to incoming ICMP requests, equivalent to a stealth firewall.

Cheers!
 

Diffusion

Senior member
Oct 19, 2000
467
0
0


<< Your namesake sucks.

Windogg
>>


Its not his fault that the product "Black Ice" choose to use one of the terms from Gibson's Sprawl series.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |