NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW1] why ICMP protocol not using port no like tcp udp??



ICMP doesn't use ports because it is not a port based service.  It is an IP type.

For example:
IP type 1 - ICMP
IP type 6    TCP
IP type 17  UDP
IP type 50  ESP
IP type 51  AH

In the ICMP arena there are about 14 define requests

Echo request, echo reply, packet transmit time, remote host time request, redirect,
remote net mask query, and so on.
FireWall-1 sets a limit on these services to allow types 3 and 8 request and reply.

Regards,
CryptoTech

"Sim, CT (Chee Tong)" wrote:

> Hi..  Dear all,
>
> 1)I wonder why ICMP not using using any port no like TCP, UDP, instead they
> are using MATCH   which is mean by MATCH?  I saw more than 1  type of ICMP
> service specified in my firewall, like ICMP-proto, ICMP-mask, ICMP request?
> What are the difference?
>
> 2)If I use normal ping service, which type of ICMP will take effect?
>
> 3)I found that when I surf the net thru my proxy server the server not only
> establish http service tcp protocol,  but also ICMP protocol with unknown
> service why?  ICMP also??
>
>
> Tong
>
>
> ==================================================================
> De informatie opgenomen in dit bericht kan vertrouwelijk zijn en
> is uitsluitend bestemd voor de geadresseerde. Indien u dit bericht
> onterecht ontvangt wordt u verzocht de inhoud niet te gebruiken en
> de afzender direct te informeren door het bericht te retourneren.
> ==================================================================
> The information contained in this message may be confidential
> and is intended to be exclusively for the addressee. Should you
> receive this message unintentionally, please do not use the contents
> herein and notify the sender immediately by return e-mail.
>
> ==================================================================
>
> ================================================================================
>      To unsubscribe from this mailing list, please see the instructions at
>                http://www.checkpoint.com/services/mailing.html
> ================================================================================



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.