Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
beaven67
New Contributor

Disable ICMP type 3 messages?

Is there a way to just disable icmp type 3 messages. I still want echo and echo replies just not unreachables.

Anyone know,

Pat Beaven

3 REPLIES 3
emnoc
Esteemed Contributor III

I was not under the impression the fortigate sent  icmp unreachable directly. Can you explain what's sending the icmp.Code type 3 message? The fortigate ? or something down wind?

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
beaven67
New Contributor

I believe the device behind the firewall sends the icmp unreachable. I want to filter out these but see no way of doing so at this point?

emnoc wrote:

I was not under the impression the fortigate sent  icmp unreachable directly. Can you explain what's sending the icmp.Code type 3 message? The fortigate ? or something down wind?

 

 

 

emnoc
Esteemed Contributor III

The diagnostic command diag debug flow is your friend, traffic allow by the fwpolicy , will only allow what's allowed.

So I bet you have ALL/ANY or icmp-any allowed by the policy on what ever is sending the icmp.Code.Type 3

 

I would audit my  fwpolicies & review my security layout. You should have no valid reason unlessed design for a host behind to have icmp.type 3s exiting your network imho

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors