Firewall rule to permit ICMP traffic
search cancel

Firewall rule to permit ICMP traffic

book

Article ID: 304285

calendar_today

Updated On:

Products

VMware Smart Assurance Network Observability

Issue/Introduction

How to configure a firewall to allow the ICMP types required by Smarts IP/APM domain

Environment

All Supported Smarts versions

Resolution

Some firewalls are configured to block ICMP traffic.  In order for Smarts to monitor a network, the following ICMP types must be allowed by the firewall 0,3,8,11. 

  • 0 Echo Reply   [RFC792]
  • 3 Destination Unreachable [RFC792]
  • 8 Echo   [RFC792]
  • 11 Time Exceeded  [RFC792] In addition, the operating system will require 5, 9, 10, for routing table updates.
  • 5 Redirect   [RFC792]
  • 9 Router Advertisement  [RFC1256]
  • 10 Router Solicitation  [RFC1256]