EMZETT.
Login

Destination Unreachable

In short: An ICMP error message that a router or target device sends back when a packet can’t reach its destination.

In more detail: Various subcodes specify the reason — e.g. “network unreachable” (no route to the target network known), “host unreachable” (target device not reachable) or “port unreachable” (no service is listening on the requested port). Important for troubleshooting, because the message immediately narrows down where in the transmission path the problem lies.

In Depth

The most important subcodes

Destination Unreachable is ICMP type 3, with several meaningful subcodes attached to a message:

Code 0: Network Unreachable    - no routing path to the target network
Code 1: Host Unreachable       - target network reachable, but target device isn't
Code 2: Protocol Unreachable   - target device doesn't know the requested protocol
Code 3: Port Unreachable       - target device reachable, but no service listens on the port
Code 4: Fragmentation Needed   - packet too big, but "Don't Fragment" set (see MTU)
Code 13: Communication Administratively Prohibited - blocked by a firewall

Practical significance for troubleshooting

For troubleshooting, this difference makes a big practical difference and allows you to narrow down exactly where in the transmission path the problem lies. “Network unreachable” points to a routing problem somewhere along the way — the responding router simply doesn’t know any route to the target network, usually because a route is missing or there’s a backbone connectivity problem. “Host unreachable” means that the target network was reached successfully, but no device answers at the specific destination address — usually because the device is switched off or the address isn’t currently assigned to anyone. “Port unreachable” indicates that the target device is running and reachable at the network level, but no service is listening on the requested port — e.g. when a server has started up but the desired web server service on it hasn’t been started or has crashed. In practice these three cases are fixed very differently: with network unreachable a routing entry has to be corrected, with host unreachable the target device itself has to be checked, and with port unreachable usually only the missing service has to be restarted.

Fragmentation needed and MTU problems

Code 4 (fragmentation needed) deserves special attention because it describes a different type of problem: a packet is larger than the maximum permitted transmission size (MTU) of an intermediate section, but at the same time has the “Don’t Fragment” bit set, which explicitly forbids splitting it into smaller fragments — the router can then neither forward the packet unchanged nor split it, and has to discard it. This message is the basis of “Path MTU Discovery”, a mechanism with which senders iteratively determine the largest possible unfragmented packet size for a particular route. If this ICMP message is blocked by a firewall (a common configuration error), Path MTU Discovery fails, and larger transfers can mysteriously hang while small requests work without problems — a classic symptom that is hard to diagnose.

Deliberate silence from firewalls

Important: many firewalls deliberately suppress destination unreachable messages (instead of returning code 13, the packet is simply dropped silently — “silent drop” or “black hole”) so as not to give attackers any information about the internal network structure and to make network scans harder. That’s why the absence of an error message doesn’t automatically mean that everything is working — from the sender’s point of view, a silent drop looks identical to a target that is simply very slow or overloaded, which is why purely timeout-based diagnosis often remains ambiguous and additional tests (e.g. with traceroute on different ports) are needed to tell them apart.

See also: ICMP types, Time Exceeded, Troubleshooting