Hacker News new | past | comments | ask | show | jobs | submit login

a properly configured (stateful) firewall permits replies to unfiltered outbound connections. you've made no corrections to anything i said, but merely added context to "filter most outbound connections" and with fair points.

but reasonable plumbers could and certainly do disagree on whether to allow any ICMP connections initiated from outside the firewall whatsoever.




The back and forth was a little confusing to me.

I forward/open IPv4 & IPv6 as needed, limited to trusted sources.

I allow IPv6 ICMP from approved countries. IIRC, this functionality goes beyond the needs of SLAAC and RA. It is a required criteria for IPv6 testing sites - but I'm not clear why.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: