When an IPv4 router or host sends an ICMP error, how much of the offending packet does it quote, and why that much?
answer
- a copy of what went wrong
- header plus a little more
- 64 bits reach the ports
- routers may quote more
- 576 bytes caps the total
basics
~20 sAn ICMPv4 error quotes the offending datagram's full IP header plus at least its first 8 payload bytes, enough to reach the TCP or UDP ports. RFC 1812 asks routers to quote as much as fits in 576 bytes.
solid answer
~50 sRFC 792 defines the data of every ICMPv4 error as the original **internet header plus the first 64 bits** of its payload, and says why: the sender uses it to match the error to a process, and transport protocols keep their port numbers in those first 64 bits. For TCP that is the source port, destination port and sequence number; for UDP it is the whole 8-byte header. RFC 1122 lets hosts send more than 8 bytes and requires the quoted bytes to be unchanged from what was received. RFC 1812 goes further for routers: they SHOULD quote as much as possible without the ICMP datagram exceeding 576 bytes, because with IP-in-IP tunnels the first 8 bytes after the outer header no longer reach any ports. A router need not undo its forwarding changes, so the quoted TTL may already be decremented.
go deeper
Remember the shape: the offending packet's IP header plus at least its first 8 payload bytes, which is where TCP and UDP keep their ports.
Explain field by field what those 8 bytes contain for TCP and for UDP, why that was judged enough in 1981, and what RFC 1122 and RFC 1812 changed.
Show how tunnels and NAT break the 8-byte assumption, why the quoted TTL and checksum differ from what was sent, and what that means for matching errors reliably.
Discuss the cost of a protocol that fixed a minimum quote size early: how later encapsulation forced larger quotes and extensions, and how ICMPv6 sized its quote from the minimum MTU instead.
## What an ICMP error carries When a router or host cannot deliver or process an IPv4 datagram, it may report the problem to the datagram's **source** with an ICMP error message: Destination Unreachable (type 3), Time Exceeded (type 11) or Parameter Problem (type 12). After the 8-byte ICMP header, each of these carries a **quotation** of the datagram that caused it. That quotation is the whole point of the message: the outer IPv4 header says who complained, the type and code say what went wrong, and the quote says **which of the sender's packets**, and therefore which of its conversations, it was about. ## The rules, in the order they were written | Source | Rule | |---|---| | RFC 792 (1981) | Quote the internet header plus the first 64 bits (8 bytes) of the original data | | RFC 1122 (1989, hosts) | At least the header and first 8 data octets; more MAY be sent; the quoted bytes MUST be unchanged from the datagram as received | | RFC 1812 (1995, routers) | SHOULD quote as much as possible without the ICMP datagram exceeding 576 bytes | | RFC 4884 (2007) | When extensions are appended, the quote is padded to at least 128 octets | The quoted IP header is quoted **whole**, options included, so its length is whatever the original header's IHL field said: 20 bytes without options, up to 60 with them. ## Why 8 bytes was enough RFC 792 states the reasoning directly: the quote "is used by the host to match the message to the appropriate process. If a higher level protocol uses port numbers, they are assumed to be in the first 64 data bits". The first 8 bytes of each common transport header contain: - **TCP**: source port (16 bits), destination port (16 bits), sequence number (32 bits). - **UDP**: source port, destination port, length, checksum: the entire UDP header. - The quoted IP header itself supplies the **Protocol** field and both **addresses**. - What a minimal quote misses: TCP's acknowledgment number, flags and window begin at byte 8 of its header, so an 8-byte quote never shows them. Together these give the sending host the protocol, both addresses and both ports, which is everything it needs to find the socket. ## Why routers were asked for more RFC 1812 says the 8-byte minimum "is no longer adequate, due to the use of IP-in-IP tunneling and other technologies". Picture a datagram encapsulated at a tunnel entry point and dropped inside the tunnel: 1. The router inside the tunnel quotes the **outer** IP header it saw. 2. The first 8 bytes after that header are the start of the **inner** IP header, not any ports. 3. The tunnel entry receives the error but cannot tell which original sender or flow to relay it to. Quoting up to 576 bytes total gives the entry point the inner headers too. The 576 figure is not arbitrary: RFC 791 requires every host to accept datagrams of up to 576 octets, so an error of that size is never too large for its destination to reassemble. ## Exact copy, with one exception RFC 1122 requires the quoted header and data to be **unchanged** from the received datagram. RFC 1812 relaxes this for routers: a router is not required to undo modifications it made while forwarding before the error was detected, such as **decrementing the TTL** or updating options. So the quoted TTL, and the quoted header checksum with it, may differ from what the sender transmitted. A receiver should therefore match on the fields that identify a flow, not on a byte-for-byte comparison with its own copy. ## Sizes in practice - Smallest ICMPv4 error: 20 (outer IP header) + 8 (ICMP header) + 20 (quoted IP header) + 8 (quoted payload) = **56 bytes**. - Largest router-generated error under RFC 1812: **576 bytes** for the entire ICMP datagram, outer header included. - ICMPv6 takes a different limit: RFC 4443 quotes as much as fits without the error exceeding the minimum IPv6 MTU of 1,280 octets. Because the checksum covers the quote, anything on the path that legitimately rewrites the quoted packet, such as a NAT restoring the private address and port per RFC 5508, must recompute the ICMP checksum as well.
- Can the quoted IPv4 header in an ICMP error differ from the header the sender actually transmitted?Yes. It reflects the datagram as it was when the error was detected. RFC 1812 lets a router leave its own forwarding changes in place, so the quoted TTL is often lower and the quoted header checksum differs with it. A NAT on the path also leaves translated addresses in the quote, which is why RFC 5508 requires the NAT to revert the embedded headers on the way back.
- What is the smallest possible ICMPv4 error datagram, and where does each byte come from?56 bytes: a 20-byte outer IPv4 header, the 8-byte ICMP header (type, code, checksum, rest-of-header word), a 20-byte quoted IPv4 header without options, and the 8 quoted payload bytes. Options in either IP header, or a longer quote, make it larger.
- Why did RFC 1812 ask routers to quote up to 576 bytes instead of 8?Because of encapsulation. Inside an IP-in-IP tunnel, the 8 bytes after the outer header belong to the inner IP header, so the tunnel entry point cannot tell which original flow an error concerns. Quoting more reaches the inner transport header. The 576-byte cap keeps the error within the datagram size every IPv4 host must be able to accept under RFC 791.
A post office returning an undeliverable letter staples a photocopy of the envelope and the letter's first line to the notice. The envelope says which building sent it; the first line names the department. The sender's mailroom routes the notice without the post office knowing anything about that building's departments. A fuller copy helps when the letter was itself stuffed inside another envelope.
saying these in an interview costs you the question
- An ICMP error carries the entire offending packet back to the sender.
- ICMP errors quote only the original IP header, with no transport bytes.
- The quoted bytes are there so the sender can retransmit the lost data.
- Every ICMP error must be padded out to exactly 576 bytes.
- A router must restore the original TTL before quoting the IP header.