EMZETT.
Login

ICMP Types

In short: The various message types that ICMP knows — each with its own type number that determines the kind of information.

In more detail: Well-known types: echo request (8) / echo reply (0) for ping, destination unreachable (3) when a destination can’t be reached, time exceeded (11) when a packet’s time to live runs out (the basis for traceroute). Each type can additionally have subcodes that specify the reason further.

In Depth

Type number and subcode

Every ICMP message carries a type number (1 byte) in its own small header, and optionally a subcode that narrows down the exact meaning further. A selection of the most important types:

Type 0:  Echo Reply             - reply to a ping
Type 3:  Destination Unreachable - destination not reachable (with various subcodes)
Type 5:  Redirect               - "use this router instead"
Type 8:  Echo Request           - ping request
Type 11: Time Exceeded          - TTL expired, basis for traceroute

Type 3 (destination unreachable) has a particularly large number of subcodes that specify the exact reason — e.g. “network unreachable” (0, no routing path known), “host unreachable” (1, target host doesn’t answer), “port unreachable” (3, no service listens on the requested port) or “fragmentation needed” (4, a packet is too big and may not be fragmented — central to Path MTU Discovery).

How traceroute exploits ICMP types

This typing allows network tools to recognise specific situations without having to evaluate free text. A traceroute program deliberately sends packets with a very low time to live (TTL starting at 1, then 2, 3, …), thereby deliberately provoking time exceeded replies from every router along the way as soon as its respective hop counts the TTL down to 0, and reconstructs the complete route to the destination from this, hop by hop:

$ traceroute emzett-digital.com
1  192.168.1.1     1.2 ms
2  10.20.30.1      8.4 ms
3  203.0.113.5     12.1 ms  (destination reached, echo reply instead of time exceeded)

Security aspects

From a security point of view, many networks and firewalls specifically filter out certain ICMP types: echo request/reply (type 8/0) is often blocked to protect against automated network scans (an attacker pinging IP addresses in rows to find out which hosts exist at all), while informational types such as destination unreachable or time exceeded are usually let through because they’re important for regular troubleshooting. Paradoxically, blocking ICMP completely can itself cause connection problems, because certain Path MTU Discovery mechanisms (which determine the maximum packet size on a transmission path) rely on working “fragmentation needed” messages — without them, connections can hang seemingly for no reason when packets that are too large are sent.

See also: ICMP, Destination Unreachable, Time Exceeded, Ping