ICMP Echo Request and ICMP Echo Reply

ICMP echo request (Type 8 Code 0) and ICMP echo reply (Type 0 Code 0) are better known as the message types used by the ping command. The format of an ICMP echo message has the standard 8 bytes of ICMP header information and then allows for a variable-length data field that can contain any kind of data. Certain size ping packets caused system crashes on some older OSs. This attack was commonly called the Ping of Death. More information can be found here:

http://www.insecure.org/sploits/ping-o-death.html. Permitting ICMP echo can lead to DoS attacks and buffer overflows as discussed in Chapter 3. It can also lead to a covert channel because information can be embedded into the data field in the ICMP echo message. An attacker that installs special software on a host internal to your network could communicate back and forth using only ICMP echo request or reply messages. Covert channels have been implemented in many different protocols, and they are impossible to completely eliminate. So, with these risks, it is understandable why a security engineer would want to stop ICMP echo messages. Unfortunately, troubleshooting would be far too difficult without it making your overall network less secure in most cases. With all that said, here are the best practices:

• Permit ICMP echo request messages to leave your network destined for any network you have reason to communicate with.

• Permit ICMP echo reply messages to your internal hosts from any network you have reason to communicate with.

• Permit ICMP echo request messages from external hosts to servers they must access (public web servers, for example). As of this writing, a random sampling of top websites yielded several that block inbound pings to their servers and several more that permit them. As an organization, you must weigh the risks of allowing this traffic against the risks of denying this traffic and causing potential users troubleshooting difficulties.

• Permit ICMP echo reply messages from any server system to the networks where that server's users reside. Echo replies from your public web server to the Internet at large is an example of this.

Deny every other ICMP echo message.

As an example, consider the very simplified Internet edge shown in Figure 6-15.

Figure 6-15. Simple Internet Edge

Figure 6-15. Simple Internet Edge

Icmp With Example

If you were writing ICMP echo access lists for router "police," the inbound Serial0 ACL would look like this:

! permit echo-request to SerialO interface of the router access-list 101 permit icmp any host 192.0.2.2 echo ! permit echo-request to public server access-list 101 permit icmp any host 126.0.64.10 echo

! permit echo-reply from anywhere to the internal network and the public server access-list 101 permit icmp any 126.0.128.0 0.0.0.255 echo-reply access-list 101 permit icmp any host 126.0.64.10 echo-reply

The ACL on the inbound Ethernet0 interface would look like this:

! permit echo-request from the internal network to anywhere access-list 102 permit icmp 126.0.128.0 0.0.0.255 any echo

The ACL on the inbound Ethernet1 interface would look like this:

! permit echo-request from the public web server to anywhere access-list 103 permit icmp host 126.0.64.10 any echo ! permit echo-reply from the public web server to anywhere access-list 103 permit icmp host 126.0.64.10 any echo-reply

Based on these ACLs, internal users can ping the web server and the Internet, the Internet can ping the web server, and the web server can ping the Internet. Of special note is that the web server cannot ping internal hosts. Based on your security policies, you can permit this to aid in troubleshooting, but be aware that many organizations consider public servers to be not much more trusted than the Internet. To make the change, you would add this line to the Ethernet0 ACL:

access-list 102 permit icmp 192.0.128.0 0.0.0.255 host 192.0.64.10 echo-reply

Continue reading here: ICMP Destination Unreachable Fragmentation Needed but DF Bit Set

Was this article helpful?

+3 -1

Readers' Questions

  • andrew
    Which icmp message type should be stopped inbound?
    1 month ago
  • There is not one specific ICMP message type that should be stopped inbound as it depends on the specific network and security requirements. However, ICMP Type 3 (Destination Unreachable) and Type 8 (Echo Request) are often blocked inbound to prevent potential security risks. ICMP Type 3 messages can provide information about network topology and potential vulnerabilities, while ICMP Type 8 messages can be used in ICMP-based attacks, such as a Ping Flood attack. It is recommended to carefully analyze the network and security needs before deciding which ICMP message types to block inbound.