<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to block ICMP Timestamp Requests</title><link>https://community.sophos.com/utm-firewall/f/management-networking-logging-and-reporting/132074/how-to-block-icmp-timestamp-requests</link><description>Hi, 
 i know that there already was a similar question here: https://community.sophos.com/utm-firewall/f/network-protection-firewall-nat-qos-ips/117583/blocking-icmp-timestamp-reply-t13-c00-and-t14-c00-not-working 
 However, this doesn&amp;#39;t really help me</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: How to block ICMP Timestamp Requests</title><link>https://community.sophos.com/thread/486810?ContentTypeID=1</link><pubDate>Thu, 20 Jan 2022 07:28:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:684733ba-3059-4d9a-969b-780d5cb23fd2</guid><dc:creator>MartinSeener</dc:creator><description>&lt;p&gt;Hi,&lt;br /&gt;thanks for the feedback. I know that we did not allow ICMP to go through from external, so this was never a &amp;quot;real&amp;quot; issue.&lt;br /&gt;Although I took the time to research and want to quickly describe my findings here for anyone else also looking into this.&lt;br /&gt;&lt;br /&gt;- You do not need ICMP even at the Firewall level from external usually&lt;br /&gt;- You may need it in VPNs when using UDP or when your interfaces don&amp;#39;t use default MTU of 1500 or provide UDP services&lt;br /&gt;- ICMP Type 8 is Echo Request (Ping), Type 3 is Dest. not reachable among others (defined in (Sub)codes) which you may need&lt;br /&gt;&lt;br /&gt;I&amp;#39;ve now disabled global ICMP altogether and only left all 3 Ping checkboxes enabled, as well as the &amp;quot;Let Traceroute from internal to external&amp;quot;. The FW itself it not traceroutable anymore from external.&lt;br /&gt;&lt;br /&gt;With this all of my IPSec VPNs still work fine, same for Road-Warrior SSL-VPN and other things.&lt;br /&gt;So this one is fixed for me now. Thanks for your help!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to block ICMP Timestamp Requests</title><link>https://community.sophos.com/thread/486781?ContentTypeID=1</link><pubDate>Wed, 19 Jan 2022 21:15:45 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1b54ecce-0d32-4576-8ee3-6886ddc9bdc1</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Martin, if you don&amp;#39;t have &amp;#39;&lt;span&gt;Allow ICMP through Gateway from external networks&amp;#39; selected on the &amp;#39;ICMP&amp;#39; tab, I don&amp;#39;t think you have a problem.&amp;nbsp; If you need some ICMP requests to come through, I prefer to make explicit firewall rules for that.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;cheers - Bob&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to block ICMP Timestamp Requests</title><link>https://community.sophos.com/thread/485819?ContentTypeID=1</link><pubDate>Sat, 08 Jan 2022 17:25:50 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:13e02a06-4b85-4161-9cc0-d14e8da711e5</guid><dc:creator>MartinSeener</dc:creator><description>&lt;p&gt;Hi,&lt;br /&gt;yes we do. But the issue is not the network behind it nor the &amp;quot;issue&amp;quot; itself. I know this is super minor to fix but I would like to give potential attackers just one less point of information.&lt;br /&gt;I think the &amp;quot;Firewall forward&amp;quot; things are not an issue since most of them only forward from internal to external. The timestamp obtained there is only from the UTM itself.&lt;br /&gt;&lt;br /&gt;Maybe we can get a solution here.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to block ICMP Timestamp Requests</title><link>https://community.sophos.com/thread/485809?ContentTypeID=1</link><pubDate>Sat, 08 Jan 2022 11:35:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5e7ed3b4-94f3-4cad-a0dc-8e6fdeb12b47</guid><dc:creator>dirkkotte</dc:creator><description>&lt;p&gt;If you use a private address-range, NATed behind some public IP#s, the problem &amp;quot;...can obtain information about your network...&amp;quot; should not exist.&lt;/p&gt;
&lt;p&gt;But i disable all &amp;quot;Firewall forward ...&amp;quot; settings without service problems.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>