Avatar

jharrison

jharrison@infosec.pub
Joined
0 posts • 5 comments
Direct message

Blocking ICMP entirely is a recipe for weird stuff happening. There’s some ICMP worth blocking - redirects, etc - but turning it off entirely A) makes debugging stuff a nightmare and B) can break some things entirely e.g. MTU probing.

permalink
report
parent
reply

Yeah. They won’t support it if you have a fault so keep the default in a box somewhere, but it’s officially kosher to provide your own. You’ll get a box on the wall (ONT) that turns PON fibre into gigabit ethernet, and that you have to use. But it’s essentially a media converter. DHCP is all you need, no authentication/login - your ONT authenticates you.

permalink
report
parent
reply

Fun fact for tiny build fans, Ethernet cables have a minimum length to achieve their stated performance.

permalink
report
reply

Used to work there. It’s fine, esp on the newer builds which you’ll be in. XGS-PON and usually plenty of backhaul capacity. Router’s crap, chuck it and buy something decent, same as any other ISP.

permalink
report
reply

One day for a work event (I masked all day) and I’m on day four. Hopefully just a bad cold and not COVID. Hope you’re doing better soon!

Not mandating masks in healthcare settings seems completely insane.

permalink
report
parent
reply