EBD> Don't drop all ICMP.  Allow unreachables to pass... else you
EBD> break path MTU discovery.

RW> Ack, good point.
RW> And the funny thing is that I started to type "maybe just
RW> ICMP type 8" but I decided to try to keep it simple instead.
RW> D'oh! :)


For anyone considering blocking ICMP, I heartily suggest a bit of
reading on the different ICMP types.  Echo request and response
have little use.  TTL expired is handy.  Unreachables are

So many firewalls sold as "appliances" have people freaking out
over normal traffic, yet feeling immune to things that slip right
through. :-(

