skip to content

When an IPv4 router discards a packet under a filtering rule, what may it send back per RFC 1812, and what does the client see?

level: middleimportance: nice to knowfreq 18%

answer

  1. a code for policy, not failure
  2. code 13 replaced two older ones
  3. silence must be allowed
  4. fast refusal or slow timeout

basics

~20 s

An IPv4 router that filters a packet may return ICMP type 3 code 13 (communication administratively prohibited) or stay silent; RFC 1812 requires the silent option and recommends allowing code 13. The client gets a prompt error, or waits out a timeout.

solid answer

~40 s

RFC 1812 defines **code 13, communication administratively prohibited**, "generated if a router cannot forward a packet due to administrative filtering". It replaced RFC 1122's codes **9** and **10** (network and host administratively prohibited, originally meant for military end-to-end encryption devices); routers SHOULD use 13. RFC 1812 also says a router's filtering MUST allow packets to be **silently discarded**, SHOULD allow code 13 to be sent instead, and MAY offer an option to never send it. For the client the difference is time: with code 13 a TCP open attempt usually fails at once, because stacks commonly treat errors during establishment as hard, and the error comes from the router's address, showing where the filter sits. With silence, TCP keeps retransmitting its SYN until the open attempt times out.

go deeper

for a junior

Recall that type 3 code 13 means a filter refused the packet, and that a filter may instead stay silent.

for a middle

Explain RFC 1812's rules: silent discard must be possible, code 13 should be possible, and codes 9 and 10 gave way to 13; then contrast what a TCP client sees in each case.

for a senior

Show you can tell a filter from a closed port from what returns, and recognise when a device forging RSTs or silence has removed that evidence.

for a principal

Weigh fast, honest refusals for legitimate clients against what code 13 reveals about the network, and who in the organisation should own that choice.

## A code for policy, not for failure Most Destination Unreachable codes describe something broken or missing: no route, no listener, a link too small. Filtering is different: the path works, and someone has decided this packet may not use it. RFC 1812 (Requirements for IPv4 Routers) gave that decision its own code: - **Type 3, code 13 — communication administratively prohibited**: "generated if a router cannot forward a packet due to administrative filtering". It replaced two older codes. RFC 1122 had defined **code 9** (communication with destination network administratively prohibited) and **code 10** (communication with destination host administratively prohibited); RFC 1812 notes these were intended for end-to-end encryption devices used by U.S. military agencies and says routers SHOULD use code 13 when they administratively filter packets. RFC 1812 also adds codes 14 and 15 for precedence violations, which are rarely seen. ## What RFC 1812 asks of a filtering router RFC 1812's section on filtering states four rules: 1. The router **MUST allow packets to be silently discarded**, with no ICMP error at all. 2. It **SHOULD allow** an ICMP unreachable to be sent when a packet is discarded, and that message SHOULD specify code 13. 3. It SHOULD allow code 13 to be configured per combination of addresses, protocols and ports it can filter on. 4. It **MAY** have an option that stops code 13 from being generated at all. So both behaviours are legitimate. Which one a network uses is a policy decision; the protocol only guarantees that both are available. Like other ICMP errors, code 13 is also subject to the rate limiting RFC 1812 asks routers to support. ## What the client experiences | | Router sends code 13 | Router discards silently | |---|---|---| | TCP open attempt | usually fails promptly; the stack reports an error naming the cause | SYN retransmitted; RFC 9293 requires at least 3 minutes of retries before the open times out, though the application may give up sooner | | UDP datagram | the error is passed up to the application (RFC 1122 says UDP MUST pass ICMP errors on) | nothing comes back; the application only sees its own timeout | | What the client learns | a filter exists, and its address is the ICMP packet's source | nothing: a filter, a lost packet and a dead host look the same | Two details explain the TCP row: - RFC 9293 does not list code 13 as either a soft or a hard error, but it notes that stacks commonly treat soft errors as hard **during connection establishment**, so in practice an open attempt that meets code 13 usually ends at once. - On an **established** connection, many stacks treat Destination Unreachable errors as soft, so a filter applied mid-connection usually shows up as stalled retransmissions rather than an immediate abort. ## Telling a filter from a closed port - **Code 13 from a router address**: a filter on the path refused the packet. - **Code 3 from the destination's address**, or a **TCP RST from the destination**: the packet arrived, and nothing was listening. - **Nothing**: no conclusion is possible; silent discard, rate limiting and loss all look alike. One implementation caution: some filtering devices answer on the destination's behalf with a TCP RST or an ICMP port unreachable instead of code 13, so that a filtered port looks closed. That is an implementation choice, not RFC 1812's code, and it removes the one clue (the router's own source address with code 13) that would reveal the filter. ## The trade-off in one line Code 13 gives legitimate clients a fast, accurate failure and tells operators where traffic stopped; silence reveals less about the network but makes every refused client wait out its timeout. Deciding which ICMP a network should emit or accept is filtering policy; the code itself, and what it means to the client, is what this message defines.

  • Why did RFC 1812 replace ICMPv4 codes 9 and 10 with code 13?
    Codes 9 and 10, from RFC 1122, split administrative prohibition into network and host variants and were intended for end-to-end encryption devices used by U.S. military agencies. RFC 1812 defined code 13 as a single general code for any router that cannot forward a packet because of administrative filtering, and says routers SHOULD use it.
  • How does a filter that sends code 13 differ, from the client's side, from one that forges a TCP RST?
    Code 13 arrives from the filtering router's own address and names the cause as administrative prohibition, so the client learns a filter exists and roughly where. A forged RST, an implementation choice some devices make, appears to come from the destination and reads as a closed port, hiding the filter and misleading diagnosis.

saying these in an interview costs you the question

  • RFC 1812 requires routers to send code 13 for every filtered packet.
  • A filtered packet always produces a port unreachable from the destination.
  • Code 13 means the destination host has no listener on that port.
  • Silently dropping filtered traffic violates the router requirements.
  • Codes 9 and 10 are still the current codes for filtered traffic.