skip to content

In ICMPv6, how does the Type field separate error messages from informational ones, and which four error types does RFC 4443 define?

level: middleimportance: should knowfreq 28%

answer

  1. one bit decides
  2. 0-127 versus 128-255
  3. unreachable, too big, exceeded, problem
  4. quote as much as fits 1280
  5. not about errors or most multicast

basics

~10 s

An ICMPv6 Type with the high-order bit clear (0-127) is an error, set (128-255) is informational. RFC 4443's errors are Destination Unreachable (1), Packet Too Big (2), Time Exceeded (3) and Parameter Problem (4).

solid answer

~50 s

RFC 4443 uses the Type field's high-order bit: `0-127` are **error messages**, `128-255` are **informational**, so a node can handle a type it does not know (unknown errors go to the upper layer, unknown informational messages are dropped). The four errors are **Destination Unreachable** (`1`, codes 0-6, from no route to port unreachable), **Packet Too Big** (`2`, carrying the next-hop MTU), **Time Exceeded** (`3`: code 0 hop limit exceeded in transit, code 1 fragment reassembly time exceeded) and **Parameter Problem** (`4`, with a Pointer to the offending octet). Each error goes to the invoking packet's source and quotes as much of that packet as fits without exceeding the 1,280-byte minimum MTU. Errors are never sent about another ICMPv6 error, and only Packet Too Big and one Parameter Problem case are sent about multicast packets. Nodes must rate-limit them.

go deeper

for a junior

Recall the split, 0-127 errors and 128-255 informational, and the four error names in order: Destination Unreachable, Packet Too Big, Time Exceeded, Parameter Problem.

for a middle

Explain which device sends each error and code, why an error quotes up to 1,280 bytes of the original packet, and the cases in which no error may be sent.

for a senior

Show you can read these errors in an incident: a code 1 or 5 that reveals a filter, a code 3 that hides a failed neighbour lookup, a Parameter Problem that explains why one header kills traffic.

for a principal

Discuss the design choices: a class bit for forward compatibility, a large quote for extension headers, and mandatory rate limiting that trades complete error reporting for protection against error storms.

## One bit decides the class Every ICMPv6 message starts with an 8-bit **Type**, an 8-bit **Code** and a 16-bit **Checksum** (RFC 4443). The **high-order bit of Type** sorts the message into a class: - **0-127: error messages**, which report that a specific packet could not be delivered or processed. - **128-255: informational messages**, such as Echo Request (`128`) and Echo Reply (`129`), and the message types that Neighbor Discovery and Multicast Listener Discovery define in their own RFCs. The point of a class bit is forward compatibility. RFC 4443 requires that an **error of unknown type** be passed to the upper-layer process that sent the offending packet, where it can be identified, while an **informational message of unknown type** is silently discarded. A node can therefore act sensibly on a message type defined after it was built. ## The four error types | Type | Name | Codes | Typical sender | |---|---|---|---| | 1 | **Destination Unreachable** | 0 no route to destination; 1 communication administratively prohibited; 2 beyond scope of source address; 3 address unreachable; 4 port unreachable; 5 source address failed ingress/egress policy; 6 reject route to destination | a router, or the IPv6 layer of the sending node; code 4 from the destination | | 2 | **Packet Too Big** | 0 (ignored) plus a 32-bit MTU field | the router whose next-hop link is too small | | 3 | **Time Exceeded** | 0 hop limit exceeded in transit; 1 fragment reassembly time exceeded | code 0 a router; code 1 the destination | | 4 | **Parameter Problem** | 0 erroneous header field; 1 unrecognized Next Header type; 2 unrecognized IPv6 option | whichever node is processing the bad header | Details worth being able to explain: - **Destination Unreachable code 3** covers failures that fit no other code, including a failure to resolve the destination's link-layer address. Codes 5 and 6 are more specific forms of code 1. No Destination Unreachable is sent for a packet dropped because of **congestion**. - **Code 4, port unreachable**, comes from the destination node when a transport such as UDP has no listener and no other way to tell the sender. - **Time Exceeded code 1** comes from the destination: RFC 8200 abandons reassembly 60 seconds after the first-arriving fragment and sends this error only if the first fragment (offset zero) was received. - **Parameter Problem's Pointer** is the octet offset of the problem in the original packet. RFC 4443's example is type 4, code 1, Pointer 40: the extension header right after the 40-byte IPv6 header holds an unrecognized Next Header value. RFC 7112 later added code 3 for a first fragment whose header chain is incomplete. - In IPv4, "fragmentation needed" is a Destination Unreachable code (type 3, code 4). In IPv6, **Packet Too Big is a separate error type**, because IPv6 routers never fragment and the message is the only path-MTU signal. ## What every error carries and where it goes An ICMPv6 error is addressed to the **source of the invoking packet**, and it includes **as much of the invoking packet as possible without the error packet exceeding the minimum IPv6 MTU** of 1,280 bytes. ICMPv4's original rule (RFC 792) quotes only the IP header plus the first 64 bits of data. The larger quote matters in IPv6 because extension headers can push the transport header far into the packet, and the receiver needs that header to find the process to notify. ## When an error must not be sent RFC 4443 section 2.4 forbids originating an error in response to: 1. another ICMPv6 error message; 2. an ICMPv6 Redirect; 3. a packet sent to an IPv6 multicast address, or as a link-layer multicast or broadcast, with two exceptions: **Packet Too Big**, so path-MTU discovery works for multicast, and **Parameter Problem code 2** for an unrecognized option whose Option Type's two highest bits are `10`; 4. a packet whose source does not identify a single node, such as the unspecified address `::`, a multicast address or a known anycast address. These rules stop error storms: one bad multicast packet must not draw an error from every receiver. ## Rate limiting An IPv6 node **MUST** limit the rate of the ICMPv6 errors it originates. RFC 4443 recommends a **token bucket**, an average rate with an allowed burst, and calls a simple one-error-per-interval timer unreasonable because it cannot cope with bursty traffic such as traceroute. It gives B=10, N=10 per second as possible defaults for a small or mid-size device, as an example rather than a protocol constant.

  • In IPv6, when may a node send an ICMPv6 error about a packet that was addressed to a multicast group?
    Normally never, because one bad multicast packet would draw an error from every listener. RFC 4443 makes two exceptions: Packet Too Big, so path-MTU discovery works for multicast senders, and Parameter Problem code 2 for an unrecognized option whose Option Type's two highest bits are 10, which RFC 8200 defines as report even for multicast destinations.
  • Why does RFC 4443 recommend a token bucket rather than a fixed timer for rate-limiting ICMPv6 errors?
    A token bucket allows an average rate with a permitted burst, so a short legitimate burst still gets its errors. Traceroute is the classic case: several probes expire at the same router in quick succession and each needs a Time Exceeded. A timer allowing one error per interval drops most of that burst, and RFC 4443 calls such an implementation not reasonable.
  • What does the Pointer field in an ICMPv6 Parameter Problem message tell the sender?
    It gives the octet offset within the original packet where the receiver found the problem, so the sender can see which header field or option was rejected. With code 1 and a Pointer of 40, for instance, the first extension header after the 40-byte IPv6 header carries a Next Header value the receiver does not recognise.

saying these in an interview costs you the question

  • ICMPv6 Time Exceeded is type 11, the same number as in IPv4.
  • In IPv6, Packet Too Big is a code of Destination Unreachable, as in IPv4.
  • Port unreachable comes from the last router before the destination host.
  • Routers send an ICMPv6 error for every dropped packet, congestion drops included.
  • An ICMPv6 error quotes only the IPv6 header plus 8 bytes of payload.
  • ICMPv6 errors are never sent about multicast packets, without exception.