skip to content

ICMP

ICMP is IP's control and error channel: it carries no application data, only why data did not arrive. Ping and traceroute are its famous consumers, and interviewers use them as the entry point.

on this pageshow

explore

questions

30

When an IPv4 host answers an ICMP echo request with an echo reply, what does that reply prove, and what does it not prove?

level: juniorimportance: must knowfreq 72%

answer

  1. network layer, not application layer
  2. answered by the IP stack
  3. no port in ICMP
  4. two-way path for small datagrams

basics

~20 s

An ICMP echo reply proves that something holding the target address has a running IP stack and that small ICMP datagrams can travel both ways right now. It proves nothing about TCP or UDP services, application health, or larger packets.

solid answer

~40 s

Ping is ICMP echo request (type `8`) and echo reply (type `0`). ICMP has no ports, and RFC 1122 requires every host's IP stack to run an echo responder, so the reply usually comes from the kernel, not from any application. A matching reply therefore proves that the address is alive, that a path works in both directions for small ICMP datagrams, and gives one round-trip time. It does not prove a service is listening, that a firewall passes the service's port, that full-size packets fit the path, or even that the intended machine answered, since some middleboxes reply on behalf of addresses they front. And a missing reply proves even less, because echo is often filtered or rate-limited.

go deeper

for a junior

Recall that ping is ICMP echo request type 8 and echo reply type 0, that ICMP has no ports, and that a reply shows the address is alive, not that a service is up.

for a middle

Explain why the IP stack answers echo regardless of application state, why a firewall can pass echo yet block a service port, and why a missing reply is weak evidence.

for a senior

Show you design health checks that test the service itself, treat echo as one layer-3 signal, and recognise middleboxes or duplicate addresses answering on a host's behalf.

for a principal

Weigh whether to keep echo answerable across an estate: its diagnostic value for operators and scanners against reconnaissance exposure, and how monitoring should avoid conflating reachability with service health.

## What an echo exchange is **ICMP** (Internet Control Message Protocol, IP protocol number `1`, defined for IPv4 by RFC 792) carries control and diagnostic messages beside ordinary traffic. Two of its messages make up the whole of what people call **ping**: - **Echo Request** — ICMP type `8`, code `0`, sent by the prober. - **Echo Reply** — ICMP type `0`, code `0`, sent back by the target. ICMP has no ports. An echo request is addressed to an **IP address**, not to a service, and it is answered by the target's IP stack, not by any application listening on it. ## Who is required to answer The requirement documents make the echo responder mandatory: - RFC 1122 §3.2.2.6: every host **MUST** implement an ICMP Echo server that receives echo requests and sends the corresponding replies. - RFC 1812 §4.3.3.6: every IPv4 router **MUST** do the same for requests addressed to the router itself. - The reply's IP source address **MUST** be the specific address the request was sent to, and the data in the request **MUST** be returned in the reply. Because the responder lives in the network stack, in most operating systems the reply is generated by the kernel without involving any user process. That is an implementation fact worth knowing: a machine whose application has deadlocked, whose disk is full or whose database is down usually still answers echo requests. ## What a reply proves When an echo reply that matches your request comes back, you have learned a narrow set of facts: 1. Something holding the destination address was up and its IP stack processed an ICMP message at that moment. 2. A path existed **in both directions** between your address and that address, for small ICMP datagrams. 3. Nothing on either path dropped ICMP echo in that direction at that moment. 4. The **round-trip time** for that one small datagram, measured against your own clock. That is genuinely useful: it separates "the address is alive and routable" from everything above the network layer. ## What a reply does not prove | Belief | Why the reply does not establish it | |---|---| | The service is up | The reply comes from the IP stack; no TCP or UDP port was involved, so a listener may be absent or hung. | | Application traffic will pass | A firewall can permit ICMP and block the service's port, or the reverse; port-based filters and ICMP filters are separate rules. | | Large packets will get through | A default echo is small; a path that cannot carry full-size datagrams answers small echoes happily (path-MTU problems are a separate subject). | | It is the machine you meant | Some middleboxes (load balancers, firewalls, translators) answer echo for addresses they front, as an implementation choice; a duplicate address also answers. | | The service will be fast | The round-trip time measures one ICMP datagram through the stacks that answer it, not the service's processing time. | In short, a reply is evidence about **layer 3 reachability of an address**, and nothing above it. ## When there is no reply The converse is weaker still. A missing reply is consistent with the host being down, but also with: - a firewall on the path or on the host dropping echo requests or echo replies; - a router's configuration option to ignore all echo requests, which RFC 1812 §4.3.3.6 says a router SHOULD offer (defaulting to answering); - rate limiting of ICMP by the responder or a device on the path; - in IPv4, a request sent to a broadcast or multicast address, which RFC 1122 says MAY be silently discarded; - ordinary packet loss, since RFC 792 is explicit that ICMP gives no delivery guarantee. So silence alone never establishes that a host is down; it only means this particular probe got no answer. ## Where this matters Host-discovery sweeps by network scanners rely on exactly these semantics: an echo reply marks an address as live, and because silence proves little, scanners also send TCP or other probes before declaring an address empty. Monitoring that equates "answers ping" with "service healthy" makes the opposite mistake. The sound habit is to treat an echo reply as one fact about one layer, and to test the service itself (a connection to its port, a real request) when the question is whether the service works. IPv6 has the same pair as ICMPv6 Echo Request `128` and Echo Reply `129` (RFC 4443), with the same meaning for a unicast target.

  • A server answers echo requests but its HTTPS service is down. How can both be true at once?
    The echo responder is part of the IP stack, which RFC 1122 requires of every host, and in most operating systems the kernel answers it without any user process. The HTTPS service is a separate process bound to a TCP port. A crashed or hung process, a full disk or a dead backend leaves the stack running, so the address keeps answering echo while the service fails. Only a probe to the service's port tests the service.
  • Does an echo reply from an IPv4 broadcast address tell you every host on that subnet is up?
    No. RFC 1122 says a host MAY silently discard an echo request sent to a broadcast or multicast address, and RFC 1812 gives routers the same freedom, so many hosts never answer a broadcast echo at all. The replies you receive show which hosts chose to answer, not which hosts exist. Directed-broadcast echo is also the basis of a classic amplification attack, which is why it is commonly disabled.

saying these in an interview costs you the question

  • A ping reply means the web service on that host is working.
  • Ping tests a specific TCP or UDP port on the target.
  • No reply to ping proves the host is powered off.
  • If small echoes succeed, large transfers on the same path must succeed too.
  • Only the target's application can generate the echo reply.
open as a page

In IPv4, how is an ICMP message carried, and what do the four parts of its 8-byte header do?

level: juniorimportance: must knowfreq 45%

basics

~20 s

ICMP rides inside an IPv4 datagram with protocol number 1. Its 8-byte header holds an 8-bit type (kind of message), an 8-bit code (specific condition), a 16-bit checksum over the whole ICMP message, and a type-dependent 32-bit word.

open as a page

Why do firewalls often block ICMP, and what breaks when an IPv4 network drops all of it?

level: juniorimportance: must knowfreq 58%

basics

~20 s

ICMP gets blocked because it has carried floods, Smurf amplification, forged redirects, covert tunnels and network mapping. Dropping all of it breaks path-MTU discovery, traceroute and fast error reporting, so large transfers stall and failed connections hang until timeout.

open as a page

In IPv4, what does an ICMP Destination Unreachable message tell the sender of a packet, and what does it not prove?

level: juniorimportance: must knowfreq 45%

basics

~10 s

An ICMP Destination Unreachable (type 3) says one IPv4 datagram was discarded before delivery and its code gives the reason. It does not prove the destination is down, and receiving none proves nothing either.

open as a page

When an IPv4 router or host sends an ICMP error, how much of the offending packet does it quote, and why that much?

level: middleimportance: must knowfreq 35%

basics

~20 s

An ICMPv4 error quotes the offending datagram's full IP header plus at least its first 8 payload bytes, enough to reach the TCP or UDP ports. RFC 1812 asks routers to quote as much as fits in 576 bytes.

open as a page

How does traceroute use the IPv4 TTL field and ICMP Time Exceeded messages to discover each router on a path?

level: middleimportance: must knowfreq 60%

basics

~20 s

Traceroute sends probes with TTL 1, 2, 3 and upward. The router at hop n expires the TTL-n probe and returns ICMP Time Exceeded code 0 from its own address, so each reply names one hop until the destination answers.

open as a page

An IPv4 client hits a closed UDP port, a closed TCP port and an unrouted network: what comes back each time, and from which device?

level: middleimportance: must knowfreq 50%

basics

~20 s

A closed UDP port draws ICMP type 3 code 3 (port unreachable) from the destination host; a closed TCP port draws a TCP RST, not ICMP; a missing route draws type 3 code 0 (net unreachable) from a router.

open as a page

If an IPv6 network blocks every ICMPv6 message at its firewalls and on its hosts, as many IPv4 networks block ICMP, what breaks and why?

level: seniorimportance: must knowfreq 45%

basics

~20 s

Blocked on hosts, ICMPv6 takes Neighbor Discovery and MLD with it, so hosts cannot resolve neighbours or routers. Blocked in transit, Packet Too Big disappears and, since IPv6 routers never fragment, large transfers hang in path-MTU black holes.

open as a page

What is ICMPv6, and which IPv4 protocols' jobs does it take over besides ICMP's own error and echo messages?

level: juniorimportance: should knowfreq 42%

basics

~10 s

ICMPv6 (RFC 4443, Next Header 58) is IPv6's control protocol. Beyond errors and echo it carries Neighbor Discovery, which replaces ARP, ICMP Router Discovery and Redirect, and Multicast Listener Discovery, which replaces IGMP.

open as a page

In IPv4, what does an ICMP Time Exceeded message (type 11) report, and which device sends each of its two codes?

level: juniorimportance: should knowfreq 42%

basics

~20 s

ICMP type 11 reports a datagram discarded because a limit ran out. Code 0, TTL exceeded in transit, comes from a router that dropped a packet whose TTL reached zero; code 1, fragment reassembly time exceeded, comes from the destination host.

open as a page

In ICMP echo, what are the Identifier and Sequence Number fields for, and how does the echoed data let a sender measure round-trip time?

level: middleimportance: should knowfreq 38%

basics

~20 s

The Identifier tags a probing session (ICMP has no ports) and the Sequence Number tags each probe; the reply copies both plus the data, so the sender matches replies and times the round trip from a send time it embedded.

open as a page

In IPv4, who sets the TTL of an ICMP echo reply, and what can the received TTL tell you about the responder and path?

level: middleimportance: should knowfreq 26%

basics

~20 s

The responder sets an echo reply's TTL from its own starting value; RFC 1812 forbids routers copying it from the request. Likely start minus received TTL estimates return-path hops, but the start is a guess and the forward path stays invisible.

open as a page

In ICMPv6, how does the Type field separate error messages from informational ones, and which four error types does RFC 4443 define?

level: middleimportance: should knowfreq 28%

basics

~10 s

An ICMPv6 Type with the high-order bit clear (0-127) is an error, set (128-255) is informational. RFC 4443's errors are Destination Unreachable (1), Packet Too Big (2), Time Exceeded (3) and Parameter Problem (4).

open as a page

What does an IPv6 router send when a packet exceeds its next-hop MTU, and how must the source react?

level: middleimportance: should knowfreq 34%

basics

~20 s

The router drops the packet and sends ICMPv6 Packet Too Big (type 2) to the source, carrying the next-hop link's MTU. The source lowers its path-MTU estimate, never below 1,280 bytes, and sends smaller packets.

open as a page

Which received IPv4 packets must never trigger an ICMP error, and what failure does each of those rules prevent?

level: middleimportance: should knowfreq 22%

basics

~20 s

RFC 1122 and RFC 1812 forbid ICMP errors about an ICMP error, a broadcast or multicast datagram, a link-layer broadcast, a non-initial fragment, or a source that is not one host. Each rule stops loops, storms or useless replies.

open as a page

How can a forged IPv4 ICMP Redirect (type 5) divert a host's traffic, and why do hardened hosts ignore Redirects?

level: middleimportance: should knowfreq 26%

basics

~20 s

An ICMP Redirect tells a host to use another next hop for a destination. Its checks only compare addresses, so an attacker on the same subnet can forge one naming itself as gateway; ignoring Redirects costs at most an extra hop.

open as a page

How did the IPv4 Smurf attack use ICMP echo and directed broadcasts to amplify a flood, and what stopped it?

level: middleimportance: should knowfreq 38%

basics

~20 s

A Smurf attacker sends ICMP echo requests, forged with the victim's address as source, to a network's directed-broadcast address; every host there replies to the victim. RFC 2644 made routers refuse directed broadcasts by default, removing most amplifiers.

open as a page

Traceroute can send UDP, ICMP Echo or TCP SYN probes; how does each mode recognise the destination, and why choose one over another?

level: middleimportance: should knowfreq 32%

basics

~20 s

In all three modes routers answer an expiring probe with ICMP Time Exceeded; only the ending differs: port unreachable for UDP, Echo Reply for Echo, SYN-ACK or RST for TCP SYN. Choose the probe the destination's filters admit.

open as a page

In IPv4, who sends an ICMP type 3 code 4 (fragmentation needed and DF set), and what does RFC 1191 make it carry?

level: middleimportance: should knowfreq 34%

basics

~20 s

A router sends type 3 code 4 when an IPv4 datagram with DF set is larger than the next link's MTU; it discards the datagram, and RFC 1191 has it report that link's MTU in the ICMP header.

open as a page

When an ICMPv4 error reaches a host, how does its stack find the TCP connection or UDP socket concerned, and why check further?

level: seniorimportance: should knowfreq 25%

basics

~20 s

The host ignores the outer header and reads the quote: its Protocol field picks TCP or UDP, and its addresses and ports, the host's own as source, name the flow. Forged errors are easy, so TCP also checks the quoted sequence number.

open as a page

You are writing the ICMP policy for an edge firewall carrying IPv4 and IPv6: what do you permit, rate-limit and drop, and why?

level: seniorimportance: should knowfreq 34%

basics

~20 s

Permit ICMP errors tied to existing flows (IPv4 types 3, 11, 12; ICMPv6 types 1 to 4), allow rate-limited echo, and drop inbound Redirects, Source Quench and deprecated types. For IPv6, follow RFC 4890's transit and local categories.

open as a page

In an IPv4 traceroute, why can a middle hop show only asterisks while later hops answer, and why might the trace never reach the destination?

level: seniorimportance: should knowfreq 38%

basics

~20 s

An asterisk means no reply arrived in time. A silent hop followed by answering hops forwards fine, but its Time Exceeded is switched off, rate-limited or filtered; a trace that never ends usually meets a filter dropping that probe type or its reply.

open as a page

Under RFC 1122 and RFC 9293, which ICMPv4 Destination Unreachable codes should make TCP abort a connection, and why do most stacks not abort established ones?

level: seniorimportance: should knowfreq 22%

basics

~20 s

TCP MUST NOT abort on Destination Unreachable codes 0, 1 or 5 (soft errors) and SHOULD abort on codes 2 to 4 (hard). Most stacks soften hard errors once synchronized, since forged ICMP could otherwise reset connections (RFC 5927).

open as a page

What is Multicast Listener Discovery in IPv6, which ICMPv6 messages carry it, and why does a host running no multicast application still send MLD reports?

level: middleimportance: nice to knowfreq 14%

basics

~10 s

MLD lets IPv6 routers learn which multicast groups have listeners on a link. It uses ICMPv6 types 130-132 (MLDv1) and 143 (MLDv2 report). Hosts also report their solicited-node groups, which Neighbor Discovery uses.

open as a page

How can ICMP echo requests and replies carry a covert tunnel through a firewall, and which traffic signals give one away?

level: middleimportance: nice to knowfreq 20%

basics

~20 s

ICMP echo carries a free-form data field, so a tunnel sends upstream data in echo requests and its own responder returns downstream data in replies. Mismatched request and reply data, odd sizes and sustained volume to one peer reveal it.

open as a page

When an IPv4 router discards a packet under a filtering rule, what may it send back per RFC 1812, and what does the client see?

level: middleimportance: nice to knowfreq 18%

basics

~20 s

An IPv4 router that filters a packet may return ICMP type 3 code 13 (communication administratively prohibited) or stay silent; RFC 1812 requires the silent option and recommends allowing code 13. The client gets a prompt error, or waits out a timeout.

open as a page

Why has sending ICMP echo requests traditionally required a raw socket and elevated privilege, and what do unprivileged ICMP echo sockets change?

level: seniorimportance: nice to knowfreq 16%

basics

~20 s

ICMP has no ports, so transport sockets cannot send it; classic ping built echo packets on a raw socket, which systems restrict because it can forge any packet. Unprivileged echo sockets let the kernel own identifier and checksum, allowing only echo.

open as a page

What does RFC 4884 add to ICMP error messages, and how does a receiver find where the quoted datagram ends?

level: seniorimportance: nice to knowfreq 8%

basics

~20 s

RFC 4884 lets certain ICMP errors carry an Extension Structure after the quoted datagram. A length attribute in a formerly reserved octet gives the padded quote's length, so receivers know where the extension header and objects begin.

open as a page

How can forged ICMP error messages reset or slow an established TCP connection, and which defences does RFC 5927 describe?

level: seniorimportance: nice to knowfreq 14%

basics

~20 s

A blind attacker who knows a connection's addresses and ports can forge ICMP hard errors to abort it, or tiny-MTU messages to cripple it. RFC 5927's defences: check the quoted sequence number, treat hard errors as soft, stop trusting ICMP for path MTU.

open as a page

Why can an IPv4 traceroute across equal-cost multipath routing report two routers at one hop, or a link between routers that does not exist?

level: seniorimportance: nice to knowfreq 16%

basics

~20 s

Routers with equal-cost paths pick a next hop per flow by hashing header fields, often including ports. Classic UDP traceroute changes the destination port on every probe, so probes take different paths and the trace mixes routers from several of them.

open as a page