Jump to content

Recommended Posts

Posted (edited)

We are using a new scheme of work which has a unit which asks you to run a TraceRT command, however the results are being blocked by the LEA ISP.

 

We have asked them to allow this so we can run the unit correctly, but they have said they will not do this because of external security threats through their firewall.

 

I have spoken to other people who have told me there is no security risk allowing this. I just wanted some other peoples thoughts on this, whether you think it should be allowed or blocked.

Edited by CommodoreS
Posted (edited)
ipconfig is run on the local pc to show ip address information, i can't see how the isp is blocking something like that. i could understand them blocking traceroute and ping. what command are they asking you to run? Edited by glen_j
Posted

I have been told:

 

"In order to allow the return icmp decrements through the firewall this will require a new inspection policy on the firewall that is not a best practice due to external security threats."

Posted

I think they really mean internal threat .

 

If you can trace route you can identify every server / router your traffic goes out via including transparent proxies .

Posted

As above. I would not want anyone doing a tracert unless it was on a machine directly connected to the internet forgoing any routers, proxies or other internal systems you may not want to be public knowledge. Personally, whoever made that scheme of work (assuming it's for secondary level and not specialist IT) hasn't thought that through very carefully.

I would suggest making a machine available as above, directly connected, where the IT staff can remote in and demonstrate it if that would cover it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...