EMZETT.
Login

ICMP

In short: Internet Control Message Protocol — doesn’t serve to transfer payload, but to report network errors and status information between devices.

In more detail: The best-known example is ping, which uses ICMP echo request/reply to check whether a host is reachable. Other ICMP types report, for example, destination unreachable or time exceeded. Runs directly at the IP level, not on TCP or UDP.

In Depth

Not a transport protocol, but pure control information

ICMP is deliberately NOT a transport protocol for application data like TCP or UDP — it has no ports, no connections, no applications “listening” on it. Instead it runs directly at the IP level and serves exclusively communication BETWEEN network devices themselves: “I couldn’t deliver your packet”, “this route no longer works”, “your packet took too long and was discarded”.

Application data:     HTTP over TCP over IP
Control information:  ICMP directly over IP (no TCP/UDP in between)

ICMP as a diagnostic tool

This special role makes ICMP the most important tool for network diagnostics: ping uses echo request/echo reply to check pure reachability, traceroute/tracert uses deliberately provoked time exceeded messages to make the complete path of a packet visible hop by hop, and routers use ICMP to automatically send senders destination unreachable messages when a destination can’t be reached. Without ICMP, troubleshooting in the network would be considerably harder — connection problems would only appear as silent failures, without any indication of WHERE exactly in the transmission path the problem lies.

Example output

A simple ping shows the typical ICMP communication:

$ ping emzett-digital.com
64 bytes from 203.0.113.5: icmp_seq=1 ttl=54 time=12.4 ms
64 bytes from 203.0.113.5: icmp_seq=2 ttl=54 time=11.8 ms

Each line corresponds to an echo request/echo reply pair; time shows the latency of the round trip, ttl the remaining time-to-live value of the received packet.

ICMP as an attack vector

Precisely because ICMP is so useful for diagnostics, it’s also misused for attacks: a “ping flood” overloads a target with masses of echo requests, and the historic “ping of death” deliberately used malformed, oversized ICMP packets to crash older operating systems. Modern systems have long been hardened against such classic attacks, which is why many firewalls still rate-limit ICMP as a precaution instead of blocking it completely.

ICMPv6 as a core component of IPv6

IPv6 uses an extended variant called ICMPv6, which takes on considerably more tasks (including the complete neighbour discovery, “Neighbor Discovery Protocol”, which in IPv4 is handled by the separate ARP protocol, as well as automatic address configuration) — so with IPv6, ICMP is no longer just “nice to have” for diagnostics but strictly required for basic network operation. Blocking ICMPv6 completely (as is sometimes done with ICMPv4 for security reasons) would effectively make an IPv6 network unusable.

See also: Ping, ICMP types, Echo Request, IPv6, ARP