ICMP

Internet Control Message Protocol (ICMP) is used to send error and operational messages and is enabled by default.

The RUCKUS Layer 3 device can send the following types of ICMP messages:

  • Echo messages (ping messages): The Layer 3 device replies to IP pings from other IP devices.
  • Destination Unreachable messages: If the Layer 3 device receives an IP packet that it cannot deliver to its destination, the Layer 3 switch discards the packet and sends a message back to the device that sent the packet to the Layer 3 switch. The message informs the device that the destination cannot be reached by the Layer 3 switch.

ICMP is used to send error messages and operational information indicating, for example, that a requested service is not available or that a host is not available. ICMP differs from transport protocols such as TCP or UDP because data is not forwarded between systems. Diagnostic tools such as ping and traceroute.

ICMP Echo Messages

By default, RUCKUS devices are enabled to reply to broadcast ICMP echo messages. Broadcast echo packets are ping requests and are triggered by ping or traceroute commands. You can disable the response to echo packets.

ICMP Destination Unreachable Messages

By default, when a RUCKUS device receives an IP packet that the device cannot deliver, the device sends an ICMP Unreachable message back to the host that sent the packet. You can selectively disable a RUCKUS device response to the following types of ICMP Unreachable messages:

  • Host: The destination network or subnet of the packet is directly connected to the RUCKUS device, but the host specified in the destination IP address of the packet is not on the network.
  • Protocol: The TCP or UDP protocol on the destination host is not running. This message is different from the Port Unreachable message, which indicates that the protocol is running on the host but the requested protocol port is unavailable.
  • Administration: The packet was dropped by the RUCKUS device due to a filter or ACL configured on the device.
  • Fragmentation-needed: The packet has the Do not Fragment bit set in the IP Flag field, but the RUCKUS device cannot forward the packet without fragmenting it.
  • Port: The destination host does not have the destination TCP or UDP port specified in the packet. In this case, the host sends the ICMP Port Unreachable message to the RUCKUS device, which in turn sends the message to the host that sent the packet.
  • Source-route-fail: The device received a source-routed packet but cannot locate the next-hop IP address indicated in the packet Source-Route option.