Disabling Forwarding Icmp Fragments - HPE FlexNetwork 10500 Series Configuration Manual

Layer 3-ip services
Table of Contents

Advertisement

The device sends the source an ICMP protocol unreachable message when the following
conditions are met:
NOTE:
If a DHCP enabled device receives an ICMP echo reply without sending any ICMP echo
requests, the device does not send any ICMP protocol unreachable messages to the
source. For more information about DHCP, see Layer 3—IP Services Configuration Guide.
The device sends the source an ICMP port unreachable message when the following
conditions are met:
The device sends the source an ICMP source route failed message when the following
conditions are met:
The device sends the source an ICMP fragmentation needed and DF set message when
the following conditions are met:
To enable sending ICMP error messages:
Step
1.
Enter system view.
2.
Enable sending ICMP
error messages.
Sending ICMP error messages facilitates network management, but sending excessive ICMP
messages increases network traffic. The device performance degrades if it receives a lot of
malicious ICMP messages that cause it to respond with ICMP error messages.
To prevent such problems, you can disable the device from sending ICMP error messages. A device
that is disabled from sending ICMP time exceeded messages does not send ICMP TTL exceeded in
transit messages. However, it can still send ICMP fragment reassembly time exceeded messages.

Disabling forwarding ICMP fragments

Disabling forwarding ICMP fragments can protect your device from ICMP fragments attacks.
To disable forwarding ICMP fragments:
The packet is destined for the device.
The transport layer protocol of the packet is not supported by the device.
The UDP packet is destined for the device.
The packet's port number does not match the corresponding process.
The source uses Strict Source Routing to send packets.
The intermediate device finds that the next hop specified by the source is not directly
connected.
The MTU of the sending interface is smaller than the packet.
The packet has DF set.
Command
system-view
Enable sending ICMP redirect messages:
ip redirects enable
Enable sending ICMP time exceeded
messages:
ip ttl-expires enable
Enable sending ICMP destination
unreachable messages:
ip unreachables enable
144
Remarks
N/A
The default settings are
disabled.

Advertisement

Table of Contents
loading

Table of Contents