[unisog] Port 0
r.kerr at cranfield.ac.uk
Thu Oct 27 16:03:33 GMT 2005
On Thu, 2005-10-27 at 09:59 -0400, Christensen, Eric wrote:
> I was reviewing my firewall logs this morning and found a few packets going
> to and from port 0. Apparently they were ICMP packets. I think that is
> probably legitimate but I'm thinking that many computers might accept these
> packets thinking they are legit when they are really attacks. If they are
> just ICMP packets you could just block them. Right?
ICMP doesn't have port numbers, if your firewall logs are showing port 0
on ICMP messages what they probably actually mean is ICMP type 0. ICMP
types are very different to to TCP/UDP ports - ICMP type 0 isn't
reserved, it's actually used for replies to pings.
More information about the unisog