EMZETT.
Login

Echo Reply

In short: The reply message to an echo request — confirms that the requested device is reachable and answers.

In more detail: If an echo reply doesn’t come, there can be several reasons: the target device is offline, a firewall specifically blocks ICMP (common for security reasons), or the packet was lost on the way. So a missing echo alone doesn’t necessarily prove that a server is down.

In Depth

Structure and matching

Echo reply is ICMP type 0 (the counterpart to type 8, the echo request) and contains the same identifier and sequence number fields as the original request, so that the sender can match the reply unambiguously — important when, for example, several ping processes run at the same time or replies arrive in a different order than the requests were sent. In addition, the recipient reflects back unchanged the payload sent along in the echo request, so that the sender can also check whether the data was altered in transit.

Example output and evaluation

Example of the output of a successful ping, in which each line represents a received echo reply:

64 bytes from 8.8.8.8: icmp_seq=1 ttl=57 time=14.2 ms
64 bytes from 8.8.8.8: icmp_seq=2 ttl=57 time=13.8 ms
64 bytes from 8.8.8.8: icmp_seq=3 ttl=57 time=15.1 ms
--- 8.8.8.8 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
rtt min/avg/max/mdev = 13.8/14.4/15.1/0.5 ms

The summary at the end provides several useful figures at once: the loss rate (see data loss), as well as the minimum, average, maximum and variation (mdev, mean deviation) of the measured latency — a high variation indicates an unstable connection, even if the average looks unremarkable.

Why a missing reply is ambiguous

If an echo reply doesn’t come, there are several typical explanations that can’t easily be told apart from the outside: the target device is actually offline or unreachable; a firewall specifically filters incoming echo requests or outgoing echo replies (many server firewalls block ICMP by default in order to be somewhat less visible to automated network scans and give potential attackers less information); or the packet was simply lost on the way without there being a configuration problem. So a missing echo doesn’t necessarily prove that a server is really down — an additional test at the application level (e.g. a direct HTTP request or a connection attempt to a known port) provides much more clarity, because it tests the actual application rather than just basic network reachability.

Security relevance

From a security point of view, note that an unlimited, free echo reply function could theoretically be misused for amplification attacks (similar to the historic Smurf attack, see Broadcast) — modern systems therefore often limit the rate at which they answer echo requests, precisely to prevent this.

See also: Echo Request, Ping, ICMP, Latency