Should Icmp Be Blocked?
Many Network Administrators Feel That Icmp Is a Security Risk, and Should Therefore Always Be Blocked at the Firewall. It Is True That Icmp Does Have Some...
Many network administrators feel that ICMP is a security risk, and should therefore always be blocked at the firewall. It is true that ICMP does have some security issues associated with it, and that a lot of ICMP should be blocked. But this is no reason to block all ICMP traffic!
What happens if ICMP is blocked?
If these ICMP messages are blocked, the destination system continuously requests undelivered packets and the source system continues to resend them infinitely but to no avail, since they are too large to pass through the complete path from the source to the destination.
Which ICMP types to block?
If you want to prevent pings to your server, you should block ICMP types 0 and 8 . You are also on the safe side blocking timestamp packages (type 13 and 14 ) and extended echo requests and responses (type 42 and 43 ).