[NANOG] Limiting ICMP

Kameron Gasso kgasso-lists at visp.net
Sun May 18 05:12:52 UTC 2008


Drew Weaver wrote:
> (do people still DDoS with ICMP these days? I see a lot of what looks like udp.pl and hardly any ICMP attack traffic anymore)

We saw a small attempted attack using ICMP a few weeks ago, but as 
you've mentioned I've mostly been seeing UDP floods (and the occasional 
TCP SYNflood still).

I do feel the need to comment that more and more lately I've been 
running into extremely frustrating situations where useful ICMP and UDP 
traffic was being filtered bidirectionally, not just rate-limited.  I 
think my favorite incident so far of this was a host that returned an 
ICMP UNREACHABLE (with a "filtered" code) in response to an ECHO REQUEST 
to itself.

Cheers,

--Kameron




More information about the NANOG mailing list