Application Scenarios for IPv4

Security of the IPv4 Protocol Stack

In normal situations, Net Unreachable messages, Time Exceeded messages, and Port Unreachable messages in ICMP can be correctly sent and received. When network traffic is heavy and a great number of errors occur, a router sends a great number of ICMP messages, which increases network traffic. Receiving and processing these messages may cause router performance to deteriorate. In addition, network attacks are usually initiated by using ICMP error messages, which may worsen network congestion.

On the NetEngine 8000 F, you can enable or disable the sending and receiving of ICMP messages.

In the inbound direction, you can control the following ICMP messages:
  • Echo Request message
  • Echo Reply message
  • Host Unreachable message
  • Time Exceeded message
  • Port Unreachable message
In the outbound direction, you can control the following ICMP messages:
  • Time Exceeded message
  • Port Unreachable message
  • Destination Unreachable message

If you disable the sending or receiving of ICMP messages, the router does not send or receive any ICMP message. This reduces network traffic and router burden and prevents malicious attacks.

Alternatively, you can limit the ICMP message rate and configure the router to discard ICMP messages with the TTL 1 and ICMP messages that carry options. This reduces router burden.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic