Disadvantages Of Sending Icmp Error Packets; Configuration Procedure - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

If a packet does not match any route and there is no default route in the routing table, the
device sends a Network Unreachable ICMP error packet to the source.
If a packet is destined for the device but the transport layer protocol of the packet is not
supported by the device, the device sends a Protocol Unreachable ICMP error packet to the
source.
If a UDP packet is destined for the device but the packet's port number does not match the
corresponding process, the device sends the source a Port Unreachable ICMP error packet.
If the source uses Strict Source Routing to send packets, but the intermediate device finds that
the next hop specified by the source is not directly connected, the device sends the source a
Source Routing Failure ICMP error packet.
If the MTU of the sending interface is smaller than the packet and the packet has DF set, the
device sends the source a Fragmentation Needed and DF-set ICMP error packet.

Disadvantages of sending ICMP error packets

Sending ICMP error packets facilitates network control and management, but it has the following
disadvantages:
Sending a lot of ICMP packets increases network traffic.
A device's performance degrades if it receives a lot of malicious packets that cause it to respond
with ICMP error packets.
A host's performance degrades if the redirect function adds many routes to its routing table.
End users are affected if malicious users send many ICMP destination unreachable packets.
To prevent such problems, you can disable the device from sending ICMP error packets.

Configuration procedure

To enable sending ICMP error packets:
Step
1.
Enter system view.
2.
Enable
error packets.
A device disabled from sending ICMP time-exceeded packets does not send ICMP TTL Expired packets
but can still send ICMP Fragment Reassembly Timeout packets.
Command
system-view
Enable sending ICMP redirect packets:
ip redirects enable
Enable sending ICMP time-exceeded
sending
ICMP
packets:
ip ttl-expires enable
Enable sending ICMP destination
unreachable packets:
ip unreachables enable
107
Remarks
N/A
The default settings are
disabled.

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents