%

Manage ICMP through PF (Packet-Filter)

Example of rules to manage ICMP with the firewall Packet-Filter (PF)

Details about this article

Article published the
; modified the
2 minutes to read

This article has 265 words.

Uniq IDentifiant: tag:doc.huc.fr.eu.org,2019-10-31:/en/sec/firewall/pf-icmp


RAW source of the article:
Commit version: 9bf3d7b


This article is also available on Gemini Protocol:
gemini://gmi.it-log.fr.eu.org/en/sec/firewall/pf-icmp.gmi


Description

Tip

Following the recommendations from my Linux firewalling ICMP about the rules to be put in place to allow or block ICMP messages, here are the adequate rules for PF, for *BSD that use Packet Filter, including OpenBSD:

Manage ICMP

Drop

(…)

icmp_block_types="{ 4 6 15 16 17 18 31 32 33 34 35 36 37 38 39 }"

(…)

block drop quick on egress inet proto icmp icmp-type 3 code 6
block drop in quick on egress inet proto icmp icmp-type 3 code 7
block drop quick on egress inet proto icmp icmp-type 3 code 8
block drop quick on egress inet proto icmp icmp-type $icmp_block_types

(…)
Warning

Pass

Info
(…)

icmp_types="{ 8 11 12 }"

(…)
block log
pass out
(…)

pass in quick on egress inet proto icmp from any to egress icmp-type { 3 code 3, 3 code 4 }
pass in quick on egress inet proto icmp from any to egress icmp-type $icmp_types

pass out quick on egress inet proto icmp from egress to any icmp-type { 3 code 3, 3 code 4 }
pass out quick on egress inet proto icmp from egress to any icmp-type $icmp_types

Or course, you can authorize all other codes that can be passed, and whose recommendations are to limit. The 3 highlighted codes are a minimum!



Enjoy-ID!
Enjoy-IT!