Stilgherrian wrote:

> No, it just means ping is bocked. Traceroute uses ping. Pings don't  
> always get allowed through any more.

More accurately, traceroute, ping and a host of other network inspection
tools use ICMP packets. And it is often a subset of ICMP that is

> block such attempts to do reconnaissance like that, for security  
> reasons, as someone said earlier. 

I suppose that host discovery is one of those concerns. Other linkers
may be able to point to other security concerns and the reason that
ICMP is being blocked. I certainly would like to know if this is
over cautious. Sometimes I think this is the case.

Have there been any exploits or attacks based on ICMP, for example?


