Re: Limiting icmp unreach response from 231 to 200 packets per second

From: Martin McCormick (martin@dc.cis.okstate.edu)
Date: 01/21/03


To: freebsd-security@FreeBSD.ORG
Date: Tue, 21 Jan 2003 10:28:46 -0600
From: Martin McCormick <martin@dc.cis.okstate.edu>

Tillman writes:
>What you're seeing is the kernel limiting ICMP responses to 200/second.
>If there are more than 200 ICMP requests per second, and you have
>net.inet.icmp.icmplim set to 200 via sysctl (the default value), this
>occurs.

        Thank you greatly. That makes perfect sense as I have
never changed that value. We do have a good and fast network so
this is more than likely legitimate but it is nice to know that
the alarm goes off if that limit for ICMP traffic is reached.
That seems like a valid limit to have at least for now.

Martin McCormick WB5AGZ Stillwater, OK
OSU Center for Computing and Information Services Network Operations Group

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Survive without ICMP?
    ... >> Can I survive if I block all ICMP requests? ... > port 0 which are a very low security risk. ... > Another is an icmp timestamp request and reply. ...
    (comp.security.firewalls)
  • IP SLA - ICMP
    ... Does anyone know the default timer for the ICMP SLA tracking statement. ... I have looked at the IP SLA guide for ICMP and I can't work out how often the ICMP requests are sent. ... This all works, however, when I tested it yesterday, the 1st ping resulted in the tracked object being removed. ...
    (comp.dcom.sys.cisco)