[unisog] Port 0

Robert Kerr r.kerr at cranfield.ac.uk
Thu Oct 27 16:03:33 GMT 2005


On Thu, 2005-10-27 at 09:59 -0400, Christensen, Eric wrote:
> I was reviewing my firewall logs this morning and found a few packets going
> to and from port 0.  Apparently they were ICMP packets.  I think that is
> probably legitimate but I'm thinking that many computers might accept these
> packets thinking they are legit when they are really attacks.  If they are
> just ICMP packets you could just block them.  Right?

ICMP doesn't have port numbers, if your firewall logs are showing port 0
on ICMP messages what they probably actually mean is ICMP type 0. ICMP
types are very different to to TCP/UDP ports - ICMP type 0 isn't
reserved, it's actually used for replies to pings.

-- 
 Robert Kerr



More information about the unisog mailing list