cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
265
Views
0
Helpful
2
Replies

Opinions on external ping

sshannon
Level 1
Level 1

I have an external SOHO customer with an 800 series router. (We are a third-party support service.) We have implemented a number of security features on the router.

What's the general opinion on disabling ping replies? Is it a good idea? The ISP has no objections to disabling pings. Should it be ACL'd to allow pings only from our network? If we deny echo-reply, does it also stop traceroute?

Thanks.

2 Replies 2

mostiguy
Level 6
Level 6

I allow ping because it is so easy for users to understand. Blocking echo-reply should not stop traceroute - traceroute uses different icmp types

osam
Level 1
Level 1

It is a good idea to disable PING replies, even traceroutes..

Check this link,

http://www.ccnaprep.com/securityciscorouters.htm

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: