
7.1 ICMP Security Overview
This section describes ICMP security principles.
The Internet Control Message Protocol (ICMP) is a sub-protocol of the TCP/IP protocol suite,
and is used to transfer control messages between IP hosts and routers. A control message conveys
information about network connectivity, host reachability and route availability.
The AR1200-S receives a large number of ICMP packets from the network, and these packets
consume a lot of CPU resources. Therefore, the AR1200-S needs to check the validity of ICMP
packets, discard specified ICMP packets, and limit the rate at which ICMP packets are received.
7.2 ICMP Security Features Supported by the AR1200-S
The AR1200-S can limit the rate at which ICMP packets are received, check the validity of
ICMP packets, discard invalid and specified ICMP packets, and ignore destination-unreachable
packets.
ICMP Packet Rate Limiting
The AR1200-S receives a large number of ICMP packets from the network, and these packets
consume a lot of CPU resources. Limiting the rate at which ICMP packets are received on the
AR1200-S can help reduce the burden of the CPU, ensuring operation of services.
The rate limit for ICMP packets can be configured globally or on an interface.
Checking Validity of ICMP Packets and Discarding Invalid and Specified ICMP
Packets
By default, the AR1200-S discards invalid ICMP packets, such as ICMP packets with the TTL
value of 0 or type 15, 16 or 17 to protect CPU resources.
The AR1200-S can be configured to discard seldom-used ICMP packets, including ICMP
packets with the TTL value of 1, with options, or with unreachable destinations. This helps
reduce the burden on the AR1200-S and protect CPU resources.
Ignoring Destination-Unreachable Packets
The AR1200-S can be configured to ignore destination-unreachable packets, including host-
unreachable packets and port-unreachable packets. If an attacker sends a large number of
destination-unreachable packets to attack the AR1200-S, the AR1200-S does not respond to
these packets and discards them directly to protect CPU resources.
7.3 Limiting the Rate of ICMP Packets
This section describes how to limit the rate at which ICMP packets are received.
Applicable Environment
The AR1200-S receives a large number of ICMP packets from the network, and these packets
consume a lot of CPU resources. Limiting the rate at which ICMP packets are received can help
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
7 ICMP Security Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
151