Security – Why block outbound ICMP

firewallicmpSecurity

This question is slightly related to "Why Block Port 22 Outbound?". I don't see how this can be a notable security risk.

Best Answer

Blocking ICMP outbound and ALL other connections from your environment is a good start for building your firewall/security policy.

But there are a lot of things that you should know before hand and take into account. A good example is when blocking all ICMP packets while allowing some other protocols such as tcp port 80 (http) could lead to problems with MTU/PMTU. If you have a network connection that uses an encapsulation such as pppoe, GRE, or one of the many others you WILL run into a large number of hard to identify MTU issues.

Good area to start reading is: