Subject: Re: Interface devices and security
To: Steve Paul <stevep@mccue.com>
From: Bill Sommerfeld <sommerfeld@orchard.arlington.ma.us>
List: port-i386
Date: 12/21/1998 20:28:01
> I am running 1.3.2 and a simple ICMP block from the examples 
> works great and doesn't interfere with any of my running services.

Note that if you turn on MTU discovery, or correspond with hosts which
do, ICMP blocks *will* interfere with many of your services, because
MTU discovery depends on the ability of systems to send and receive
certain ICMP error messages -- specifically, destination
unreachable/fragmentation needed.

					- Bill