Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista Security > Return ICMP port unreachable on nonlistening socket

Reply
Thread Tools Display Modes

Return ICMP port unreachable on nonlistening socket

 
 
Petr Pisar
Guest
Posts: n/a

 
      11-12-2009

Hello,

common TCP/IP implemetations return ICMP port unreachable error packet
when somobody send packet to port where no server is listening. This was
true even in Windows XP.

However Windows Vista Business SP2 behaves differently. It drops the
packet silently even if given port is allowed for incoming communication
in Advanced firewall settings. (And yes, I'm pretty sure it's really
allowed because in the pfirewall log is not message about dropping.)

I guess this is yet another Windows feature trying to smarter and more
secure than user.

Does anybody know how to get classic behaviour back?

-- Petr
 
Reply With Quote
 
 
 
 
Petr Pisar
Guest
Posts: n/a

 
      11-12-2009

On 2009-11-12, Mr. Arnold <> wrote:
> Petr Pisar wrote:
>>
>> common TCP/IP implemetations return ICMP port unreachable error packet
>> when somobody send packet to port where no server is listening. This was
>> true even in Windows XP.
>>
>> However Windows Vista Business SP2 behaves differently. It drops the
>> packet silently

[...]
>
> Maybe, IPsec is enabled on the machine with a policy to block ICMP. A
> drop message by the FW wouldn't be logged, as IPsec sits in front of the
> FW and blocks.
>
> Other than IPsec with an IPsec policy or something else like a 3rd
> personal FW solution running on the machine that's doing the blocking,
> then nothing else on Vista other than Vista's FW is going to be blocking.
>

I have installed the machine and I'm the only administrator of the
system. No third party packet filters nor IPsec policies are installed
or active. FYI, ICMP echo request and replies flow normally.

I found the same complaint on web
(http://www.vistax64.com/vista-securi...-requests.html), but without solution.

Can anybody at least confirm that it's a bug/feature of Windows Vista?
(I don't have any other system to compare it.)

-- Petr
 
Reply With Quote
 
OgL
Guest
Posts: n/a

 
      11-27-2009
> Can anybody at least confirm that it's a bug/feature of Windows Vista?
> (I don't have any other system to compare it.)


It is a "feature":
http://technet.microsoft.com/en-us/l...57(WS.10).aspx

And I still have not found any way to disable it.

Ondrej
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Problems with ActiveSync and older Windows CE Michael Gross ActiveSync 5 08-05-2009 08:06 PM
cannot install Vista ACPI error Salsakidd Windows Vista Installation 6 10-10-2007 10:12 AM
MS ActiveSync 4.2 problem Little_Monster ActiveSync 13 09-19-2006 04:14 PM
Stop Error 0x0000007b Louis LeBrun Windows Vista Installation 17 07-05-2006 09:00 AM
Help !!! Unable to connecte Asus 620 Nick ActiveSync 4 05-23-2005 11:56 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59