Re: ICMP and ip prohibit rule

markryde@xxxxxxxxx a écrit :

ip rule add from to prohibit
and ping from to I do get
"connect: Network is unreachable" message. But I sniffed for all ICMP
traffic on and there was no ICMP packet.

What ICMP packet ?

I would appreciate if anybody can give a simple example where you use
a prohibit rule and send some ping/start ssh etc, and you can catch an
ICMP packet as a result.
(According to "man ip", it should be a speical kind of ICMP message:
"communication administratively prohibited")

If the rule is on the sender, then it returns an error when a local process tries to send a packet that matches it. It sends an ICMP error message to the sender only when it is on an intermediate router.

Relevant Pages

  • Re: Help - Tried almost everything!
    ... still have no answer why the ICMP still goes out every ... >> a periodic router advertisement. ... >>>|>>installed the Firewall after I suspected a problem ... but this is just an ICMP packet that's ...
  • RE: ICMP unreachable question
    ... If I understood you correctly you are referring to the ICMP Error ... will be used to carry the MTU used for the link ... I'm interested in a particular ICMP packet which seems to change the ... This list is provided by the SecurityFocus Security Intelligence Alert ...
  • Re: Traceroute anomaly
    ... RFC 1122, "Requirements for Internet Hosts - Communication Layers", ... interest regarding this disputed "change" to ICMP processing concerns ... ICMP packet ought not to be created - about whether or not an ICMP ... The ICMP-based traceroute relies on undocumented behaviour no matter ...
  • Re: ICMP and discard oversize frame
    ... I am running a FreeBSD router with two ethernet cards. ... the MTU to 800 in order to generate ICMP packet "Fragmentation needed ... But there is no ICMP sent. ...
  • Re: pf(4) + fetch(1) +
    ... # pass tcp, udp, and icmp out on the external interface. ... pass out on $ext_if proto tcp all modulate state flags S/SA ... which result in an icmp packet indicating that the packet was dropped as fragmentation was needed but DF flag was set. ...