Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
beaven67
New Contributor

Disable ICMP type 3 messages?

Is there a way to just disable icmp type 3 messages. I still want echo and echo replies just not unreachables.

Anyone know,

Pat Beaven

3 REPLIES 3
emnoc
Esteemed Contributor III

I was not under the impression the fortigate sent  icmp unreachable directly. Can you explain what's sending the icmp.Code type 3 message? The fortigate ? or something down wind?

 

 

 

PCNSE 

NSE 

StrongSwan  

beaven67
New Contributor

I believe the device behind the firewall sends the icmp unreachable. I want to filter out these but see no way of doing so at this point?

emnoc wrote:

I was not under the impression the fortigate sent  icmp unreachable directly. Can you explain what's sending the icmp.Code type 3 message? The fortigate ? or something down wind?

 

 

 

emnoc
Esteemed Contributor III

The diagnostic command diag debug flow is your friend, traffic allow by the fwpolicy , will only allow what's allowed.

So I bet you have ALL/ANY or icmp-any allowed by the policy on what ever is sending the icmp.Code.Type 3

 

I would audit my  fwpolicies & review my security layout. You should have no valid reason unlessed design for a host behind to have icmp.type 3s exiting your network imho

 

 

 

PCNSE 

NSE 

StrongSwan  

Top Kudoed Authors