An IPv4 client hits a closed UDP port, a closed TCP port and an unrouted network: what comes back each time, and from which device?
answer
- who has a signal of its own
- UDP has no control bits
- TCP answers for itself
- routers report missing routes
- read the error's source address
basics
~20 sA closed UDP port draws ICMP type 3 code 3 (port unreachable) from the destination host; a closed TCP port draws a TCP RST, not ICMP; a missing route draws type 3 code 0 (net unreachable) from a router.
solid answer
~50 sIt depends on whether the failing layer has its own way to say no. **UDP to a closed port:** UDP has no control bits, so RFC 1122 says the destination host SHOULD send ICMP **type 3 code 3, port unreachable**. **TCP to a closed port:** TCP signals for itself; under RFC 9293 a segment for a connection that does not exist gets a **RST**, so no ICMP is involved (though TCP MUST still accept a port unreachable if one arrives). **No route:** the router that cannot forward sends **type 3 code 0, net unreachable**; if the network is directly attached but the host does not answer ARP, that last router sends **code 1, host unreachable**. The ICMP packet's source address tells you which device spoke: the destination itself, or a router somewhere short of it.
code
pseudocode · 17 lineson_datagram_addressed_to_me(dgram):
quiet = dgram.dst is broadcast or multicast # RFC 1122: no ICMP error
if dgram.protocol not supported:
if not quiet:
send_icmp(type=3, code=2, quote=dgram) # protocol unreachable
elif dgram.protocol == UDP:
if no socket bound to dgram.udp.dst_port:
if not quiet:
send_icmp(type=3, code=3, quote=dgram) # port unreachable
else:
deliver(dgram)
elif dgram.protocol == TCP:
if no connection or listener matches:
if not quiet and not dgram.tcp.RST:
send_tcp_reset(dgram) # RST, no ICMP
else:
deliver(dgram)go deeper
Recall the three outcomes: port unreachable for closed UDP, a RST for closed TCP, net unreachable from a router when there is no route.
Explain why UDP needs ICMP and TCP does not, and how the ICMP packet's source address and code identify the device that gave up on the datagram.
Show you can tell a closed port from a filter or a routing hole from what returns, and that you know when the evidence is missing or forged.
Consider how much a service estate should reveal through these answers, and how clients should behave when a filter turns a fast refusal into a slow timeout.
## Three failures, three different answers A client that sends traffic toward a destination can fail at three different places, and each place answers differently. The rule underneath is simple: **a layer with its own way of saying no uses it; ICMP fills in where nothing else can.** | What the client sends | What comes back | Who sends it | The rule | |---|---|---|---| | UDP datagram to a port with no listener | ICMP type 3, code 3 (port unreachable) | the destination host | RFC 1122: UDP SHOULD send a port unreachable | | TCP SYN to a port with no listener | TCP segment with RST set | the destination host's TCP | RFC 9293: a closed connection answers any segment except a reset with a reset | | Any datagram toward a network with no route | ICMP type 3, code 0 (net unreachable) | a router on the path | RFC 1812: generated when no forwarding path exists | | Any datagram to a host that does not answer ARP on its final network | ICMP type 3, code 1 (host unreachable) | the last-hop router | RFC 1812: no path to a host on a directly connected network | In the examples below the client is `192.0.2.10`, the server is `203.0.113.20`, and a router at `192.0.2.1` has no route at all for `198.51.100.0/24`. ## UDP to a closed port UDP's header has ports, a length and a checksum, and nothing else: no flags, no way to refuse. So when a datagram for UDP port 5000 reaches `203.0.113.20` and nothing is bound there, the host's IP layer is the only thing that can answer. RFC 1122 says that if a datagram arrives for a UDP port with no pending listener, UDP **SHOULD** send an ICMP Port Unreachable, and RFC 1122's ICMP section describes code 3 as being for a transport that "has no protocol mechanism to inform the sender". The error comes **from the server's own address** and quotes the client's IP header and UDP header. Two consequences for the client: - It arrives **asynchronously**, after the send has already succeeded locally. RFC 1122 leaves the application responsible for matching it to what it sent. - How it surfaces is up to the host's socket interface. A common implementation choice is to report it on a later call, and only for a socket tied to that one peer. ## TCP to a closed port TCP has its own refusal. RFC 9293: if the connection does not exist (CLOSED), a reset is sent in response to any incoming segment except another reset, and "a SYN segment that does not match an existing connection is rejected by this means". The client's open attempt fails with a **RST from `203.0.113.20`**, which applications usually report as "connection refused". No ICMP message is generated. The ICMP path is not forbidden for TCP, only unnecessary: RFC 1122 says a transport with its own mechanism (TCP's RST) MUST nevertheless accept an ICMP Port Unreachable for the same purpose, and RFC 9293 lists an ICMP Port Unreachable among the ways an open attempt can fail. ## No route on the path When the router `192.0.2.1` receives a datagram for `198.51.100.7` and its forwarding table has nothing covering it, it discards the datagram and returns **type 3 code 0, net unreachable**, from its own address. The destination never sees the packet. A close relative is **code 1, host unreachable**: the last router does have a route (the network is directly connected), but the target host does not answer ARP, so the router cannot deliver the frame. RFC 1812 requires a host code (host unreachable or destination host unknown) rather than net unreachable whenever other hosts on that network might still be reachable, so senders do not write off a whole network. ## Reading what came back 1. **Is it ICMP or a TCP RST?** A RST is TCP's own answer from the destination; an ICMP error can come from anyone on the path. 2. **Which address sent the ICMP?** RFC 792 lists codes 0, 1, 4 and 5 as router-generated and codes 2 and 3 as host-generated, so the source address locates the failure. 3. **What does the quoted header say?** It identifies which of your datagrams died. 4. **Nothing at all?** Rate limiting, silent filtering and lost errors all look the same; only a timeout settles it. One caution: some filtering devices answer on the destination's behalf with a RST or a port unreachable. That is an implementation choice, not one of these RFC rules, and it makes a filter look like a closed port.
- Why does UDP depend on ICMP to report a closed port while TCP does not?TCP's header carries control bits, so a host can refuse with a RST from TCP itself. UDP's header has only ports, length and checksum, so RFC 1122 has the host use ICMP port unreachable for a transport that "has no protocol mechanism to inform the sender". TCP must still accept a port unreachable if one arrives, but it does not generate one.
- How can a client tell whether a router or the destination generated an ICMP unreachable?Compare the ICMP packet's source address with the destination quoted inside it. If they match, the destination answered, typically with code 2 or 3; if they differ, a router on the path did, which is where RFC 792 places codes 0, 1, 4 and 5. A filtering device that answers on the destination's behalf can blur this.
- Why might a UDP application see a port unreachable only on a later call, or never?The error arrives asynchronously, after the send has returned, and RFC 1122 leaves the application to match it to what it sent. How it surfaces is an implementation choice of the socket interface; a common one reports it on a later operation and only for a socket tied to that single peer. The error itself can also be rate-limited or lost.
Undeliverable post comes back stamped by whoever gave up: the sorting office stamps 'no such route' when it cannot send the letter on, while the house itself returns 'nobody here by that name'. The stamp's origin tells you how far the letter got.
saying these in an interview costs you the question
- A closed TCP port answers with ICMP port unreachable, just like UDP.
- Port unreachable comes from the last router before the server.
- No reply to a UDP datagram means the port is closed.
- A UDP send to a closed port fails immediately inside the send call.
- Host unreachable means the host refused the connection.