> Date: Wed, 23 Jul 2003 14:06:09 -0400 (EDT)
> From: Dave Temkin <[EMAIL PROTECTED]>
> 
> Unless of course I block ICMP for the purposes of denying traceroute but
> still allow DF/etc.  Then it's not "broken" as you say.

And where do the ICMPs come from if the DF bit results in a failure?
Surely not an RFC1918 address.
-- 
R. Kevin Oberman, Network Engineer
Energy Sciences Network (ESnet)
Ernest O. Lawrence Berkeley National Laboratory (Berkeley Lab)
E-mail: [EMAIL PROTECTED]                       Phone: +1 510 486-8634

Reply via email to