Solved

icmp ,snmp

Posted on 2009-04-01
2
785 Views
Last Modified: 2012-05-06
Hi,

Can any one explain me the ports numbers used for icmp both for echo request and reply

Any standard piece of code for blocking echo request and echo reply ;please help with the code for both router and pix;

Please help with the port for snmp also

thx
0
Comment
Question by:phoenix26
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 24048858
Here is a good reference for ICMP type messages:

http://www.iana.org/assignments/icmp-parameters

To block ICMP echo and echo reply (inbound I assume):

Router:

access-list 150 deny icmp any any echo
access-list 150 deny icmp any any echo-reply
access-list 150 permit ip any any    <--add if you are allowing everything by default

int <wan interface>
ip access-group 150 in

PIX:

access-list outside_access_in extended deny icmp any any echo
access-list outside_access_in extended deny icmp any any echo-reply
access-group outside_access_in in interface outside


SNMP polling uses UDP 161
SNMP Traps use UDP 162
0
 

Author Closing Comment

by:phoenix26
ID: 31565653
Excellent feedback Thanks a lot
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question