ICMP is how network devices report errors and diagnostic conditions about IP traffic. IP itself cannot say anything went wrong: a router that cannot deliver a packet discards it silently. ICMP carries those reports back. It is not a transport, has no ports, and blocking all of it breaks path MTU discovery.
- No ports, no connections, no data of yours. It reports on other traffic
- Runs as IP protocol 1, beside TCP and UDP rather than above them
- Type 3 code 4 must never be blocked, in either direction
- Routers generate it at low priority, which is why a hop looks slow
- ICMPv6 is mandatory: neighbor discovery is built on it
On this page
FundamentalsWhat it is and is not
ICMP sits beside IP at the network layer rather than on top of it, and the distinction explains most of its behavior.
It is not a transport protocol. TCP and UDP carry your data and have port numbers so many applications can share one address. ICMP carries no application data and has no ports at all. A firewall rule for it names a protocol and a message type, never a port, which is the first thing that confuses people writing one.
It is not reliable and does not try to be. An ICMP message is sent once. If that message is lost on the network, nothing retransmits it and nobody notices. The protocol is a courtesy, not a guarantee.
It reports errors about other traffic. Almost every ICMP message is generated because another packet could not be delivered, and it includes the beginning of that original packet so the sender works out which connection the error concerns.
It is generated at low priority. Routers treat producing ICMP messages as background work behind forwarding real network traffic. That is why a traceroute hop shows 80 milliseconds while forwarding at line rate, and it is the single most misread thing in network diagnostics.
The message itself is small. An ICMP header is eight bytes: a type, a code, a checksum, and four bytes whose meaning depends on the type. After that header comes as much of the original packet as will fit, normally its IP header plus the first eight bytes of data.
Those eight bytes are the useful part, because for TCP or UDP they contain the source and destination ports, which is how the receiving host works out which of its connections the error message is about.
That structure explains why ICMP sits at the network layer rather than above it. It is carried directly inside an IP packet, as protocol number 1, with no transport layer between them. An ICMP message is not sent over the internet the way your data is: it is a report about your data, traveling in the same envelope.
Message typesThe types worth knowing
There are dozens of ICMP message types and about six matter in practice. Each message header carries a type, and most carry a code narrowing the meaning.
| Type | Code | Name | What it means |
|---|---|---|---|
| 0 | 0 | Echo reply | The answer to a ping |
| 3 | 0 | Destination net unreachable | No route to that network |
| 3 | 1 | Destination host unreachable | The network was reached, the host was not |
| 3 | 3 | Port unreachable | Nothing is listening on that UDP port |
| 3 | 4 | Fragmentation needed | Too large, and the DF bit was set |
| 5 | 0 | Redirect | Use a different gateway for this |
| 8 | 0 | Echo request | A ping |
| 11 | 0 | Time exceeded | The TTL hit zero, which is how traceroute works |
Three rows carry most of the practical weight.
Type 3 code 4 is the ICMP message that must never be blocked. It says a packet was too large for a link and could not be fragmented. Without that error, the sender never learns and keeps retransmitting a packet that will never arrive. This is the fragmentation problem behind most VPN tunnels that connect and then hang.
Type 11, time exceeded, is what traceroute reads. Each router that decrements a TTL to zero announces itself with this ICMP message, which is the entire mechanism behind the tool.
Type 3 code 3, port unreachable, is how UDP reports a closed port. UDP has no way to refuse a connection, so the network layer on the destination host sends this error instead. It is also what tells a Linux traceroute it has reached the destination.
Do not block itWhy blocking all of it is a mistake
Blocking ICMP wholesale is a common hardening instruction and it is wrong, for one specific reason that is worth understanding rather than accepting.
Path MTU discovery is how two hosts work out the largest packet the network path between them can carry.
The sender sets the do not fragment bit in the IP header, and if a link along the way is too small, the router there returns an ICMP type 3 code 4 message naming the size that would fit. The sender adjusts and continues.
Block that error message and the mechanism has nothing to work with. The sender keeps transmitting packets that are silently discarded, retransmits them, and they are discarded again. Small packets get through because they fit, so the connection establishes and looks healthy. Anything larger vanishes.
The symptom is precise and nobody blames ICMP for it: a connection that opens, exchanges a few small messages successfully, and then hangs the moment real data flows. Web pages that start loading and stop. A VPN that connects and cannot open a file share. An SSH session that authenticates and freezes on the first large output.
Two other things break more quietly.
Traceroute stops working, which costs you the network diagnostic tool you would use to find any of this.
Some redundancy mechanisms slow down, because a host waiting for a TCP timeout takes far longer to fail over than one that received a destination unreachable message immediately.
The correct policy is not to allow everything. It is to allow the ICMP messages the protocols need and block the rest.
A policyWhat to allow, and what to drop
A workable inbound policy at an internet edge, by message type.
Allow type 3 code 4, fragmentation needed. Always, in both directions, without exception. This is not a preference.
Allow type 3 generally, the destination unreachable messages, or at least codes 0, 1 and 3. They make network failures fast and explicit rather than slow and mysterious.
Allow type 11, time exceeded. It costs nothing and it is what makes traceroute work when you need it.
Rate limit type 8, the echo request. Allowing ping to your internet edge is fine and useful. Allowing unlimited ping is a small amplification opportunity, and a rate limit removes it while keeping the diagnostic.
Drop type 5, the redirect, at any boundary you do not control. That message tells a host to use a different gateway, which is exactly what an attacker on the local network would like to send.
Drop timestamp and address mask requests, types 13 and 17. They leak information and nothing legitimate uses them.
On IPv6 the calculation changes entirely, and this matters. ICMPv6 is mandatory. Neighbor discovery, which replaces ARP, is ICMPv6. Router advertisements are ICMPv6. Path MTU discovery is more important on IPv6 than on IPv4, because routers do not fragment at all. Blocking ICMPv6 broadly does not harden an IPv6 network, it stops it working.
SecurityThe security concerns, in proportion
ICMP does have a genuine security history, and the concerns are narrower than the blanket blocking suggests.
Reconnaissance. Ping sweeps map which addresses on a network respond. Real, and mitigated by the fact that anyone scanning will use TCP probes when ICMP is blocked, so the benefit of blocking is smaller than it looks.
Floods. An ICMP flood is a volumetric attack, and the smurf attack of the 1990s amplified it using broadcast addresses. That specific attack has been dead for two decades, since networks stopped forwarding directed broadcasts. Rate limiting handles what remains.
Tunneling. Data can be hidden inside the payload of echo request messages, and tools exist to do it. It is a real exfiltration channel and one of many, and blocking ICMP moves the same data into DNS instead.
Redirects. The one worth taking seriously on an untrusted segment, because accepting a redirect from an attacker reroutes traffic through them. Drop these at any boundary you do not control, and modern operating systems ignore them by default anyway.
Weigh those against breaking path MTU discovery for every connection. The trade is not close.
PitfallsWhere people go wrong
Blocking all ICMP as a hardening step. It appears on old checklists and it breaks path MTU discovery, which produces hangs nobody attributes to the firewall.
Concluding a host is down because ping fails. Plenty of hosts and most cloud instances drop echo requests by default. Test the actual service on its port.
Blocking ICMPv6. Not the same decision at all. Neighbor discovery and router advertisement are ICMPv6, so blocking it broadly stops the network functioning.
Writing an ICMP firewall rule with a port. There are no ports. A rule naming one either fails to apply or matches nothing, depending on the platform.
Blaming the slow hop in a traceroute. ICMP replies are generated at low priority, so a busy router answers slowly while forwarding perfectly. Only latency that persists to the end is real.
Assuming ICMP carries data. It carries error reports and the first bytes of the packet that caused them. It is not a transport for your traffic, which is what makes tunneling over it notable rather than normal.
ComparisonICMP against the two transports, on what each one is actually for
| Criterion | ICMP | TCP | UDP |
|---|---|---|---|
| Carries application data | No | Yes | Yes |
| Has port numbers | No | Yes | Yes |
| Establishes a connection | No | Yes | No |
| Retransmits when lost | No | Yes | No |
| Reports delivery errors | Yes | Indirectly | No |
| Safe to block entirely | No | Sometimes | Sometimes |
| Required for path MTU discovery | Yes | No | No |
| Runs as IP protocol | 1 | 6 | 17 |
The sixth row is the argument of this whole page. TCP and UDP can be filtered per port with confidence. ICMP cannot be blocked wholesale without breaking the protocols above it.
FAQFrequently asked questions
What is ICMP used for?
Reporting errors and diagnostic conditions about IP traffic. It carries the messages that say a destination is unreachable, a packet was too large, or a TTL expired.
Does ICMP use ports?
No. It has no port numbers at all. Messages are identified by a type and a code, which is what a firewall rule for it names.
Is ICMP a transport protocol?
No. It carries no application data. It runs directly on IP as protocol number 1, alongside TCP and UDP rather than above them.
Should I block ICMP on my firewall?
Not entirely. Allow type 3 code 4 always, allow type 11, rate limit echo requests, and drop redirects and timestamp requests. Blocking everything breaks path MTU discovery.
What is type 3 code 4?
Fragmentation needed. It tells a sender that a packet was too large for a link and could not be split because the do not fragment bit was set. Blocking it causes connections that open and then hang.
Why does ping fail when the website works?
Because the host or a firewall drops echo requests while still serving traffic on its real ports. A ping timeout is not evidence that anything is down.
How does traceroute use ICMP?
It sends packets with deliberately short TTLs, and each router that discards one announces itself with a type 11 time exceeded message. That list of announcements is the trace.
Can ICMP be used to attack a network?
Historically yes, through floods and the smurf amplification attack. Modern networks do not forward directed broadcasts, and rate limiting handles what remains.
Is ICMPv6 the same thing?
Related and far more important. Neighbor discovery and router advertisement are both ICMPv6, so blocking it broadly stops an IPv6 network from working at all.
What is an ICMP flood?
Sending large volumes of echo requests to overwhelm a target. It is a volumetric denial of service, and rate limiting rather than blocking is the proportionate answer.
Why is one traceroute hop slow?
Because generating an ICMP reply is a low priority task for a busy router. Only latency that continues through every subsequent hop indicates a real problem.
Can data be hidden inside ICMP?
Yes, in the payload of echo requests, and tools exist for it. It is one exfiltration channel among many, and blocking ICMP moves the same traffic into DNS instead.
Keep readingRelated concepts
Read next · Remote access What Is an IPsec VPN? A tunnel that connects and then hangs is almost always fragmentation needed being dropped somewhere. Open this next11 min- Network security · 14 min What Is a Firewall? An ICMP rule names a type and a code, never a port, which is the first thing people get wrong writing one.
- Diagnostics · 11 min Ping and Traceroute Both tools are built entirely on ICMP, and the low priority replies explain the output people misread.
- Diagnostics · 12 min Reading a Wireshark Capture Without Drowning in Packets The protocol behind the error messages that appear beside a failed handshake.
- Diagnostics · 11 min Packet Loss vs Latency, and Why They Feel the Same to Users Why one hop looks terrible and the ones after it look fine.
- Diagnostics · 12 min MTU and Fragmentation, and the Numbers Worth Memorizing The protocol the whole mechanism depends on.
- Fundamentals · 10 min The IPv4 Header, Field by Field and in Order of Usefulness The protocol that reports what the header fields caused.