| Zigzag 2005-02-02, 6:39 am |
| Hi TigerTiger,
Interesting question that one.
The default filter rules for Netgear are to block everything coming in
(including ICMP ping) and allow everything going out.
However, when I tried the symantec security check
(http://symantec.security.com/) one of the things it picked up was a
response to ICMP ping. Odd.
Even so, as part of the efforts to get things working I
1) entered the Xbox IP in the dmz,
2) explicitly stated that ALL incoming and outgoing traffic was to be
allowed for the Xbox IP,
both of which I would expect to allow ICMP ping.
Your post about the ping triggered a long forgotten memory so I went to the
Netgear support site and found this:
"Microsoft is intentionally sending a spurious ICMP packet to your router
when it runs XBox Live Network - as a warning about a problem that might
happen later. This (correctly) causes the NETGEAR router to terminate the
session. The ICMP packet was Microsoft's attempt to solve another problem
that routers from various companies were having with their service and ICMP.
Instead, it caused a different problem.
Both problems may be fixed in the future, in the meantime, you can try these
steps to get routers that use filter rules to connect to XBox Live Network.
Note that blocking ICMP - as recommended - in limited situations may cause
your router to intermittently disconnect from the Internet. Also note that
if you are already using filters, you'll need to add the new filters so that
the existing ones continue working properly.
Upgrade to the latest router firmware.
Open ports 88 and 3074. (There appear to be non-NETGEAR sources that say
this is unnecessary, however it is.) "
There are also some filter rules on this page which I haven't quite worked
out at this moment in time.
If anybody wants to check these out they can go the Netgear support site
http://kbserver.netgear.com/main.asp and enter icmp ping in the search box.
This will give a list of relevant pages including "using Xbox live with
netgear routers".
I need to clarify that I have NOT tried these recommendations so cannot
vouch for them.
I still need to establish why I am sending a ping response (symantec check)
when the blurb explicitly says it should be blocked.
Also I still don't understand why the router was blocking the security
update but is now quite happily allowing the content download and the game
(and other games) to run live.
As I stated in my original post, it's not me who plays this game, I would be
an embarrassment to any team in a deathmatch, but my son who enjoys seeing
his old man being fragged to millions of pieces. I think we may have some
issues to resolve here.
Thanks for your help.
Zig
|