Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ICMP Packets

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 6 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      TomT
      last edited by

      Hi

      I have a SIP trunk which registers from a specific IP Address and works fine. I see inbound traffic on 5060 every few minutes.

      Looking at my logs I also get ICMP packets from 2 IP Addresses in the same range as the SIP carrier.
      These appear every couple of seconds. All day everyday.

      The addresses are nothing to do with the trunk, the carrier only specifies you need to allow the IP Address I've allowed.
      They are being blocked, but should the carrier be sending them constantly ?

      I am going to email them, just wondered if anyone had seen anything similar.

      Thanks

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        No, probably because I'm not blocking ping.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          ^ exactly I really don't see a legit reason to block icmp reply.. Don't you want to be able to tell if your pfsense atleast up answering ping if your away?  Sure many services will check to see if they can ping you before sending traffic.  If you allowed those, the frequency could drop off, etc.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • T
            TomT
            last edited by

            Thanks for the replies.
            The default installation seems to have blocked ping (ICMP), do I need to add a rule to allow it ?

            Or is it an option within the configuration ?

            Thanks again

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              All inbound traffic is blocked on WAN by default.  You have to add a rule to allow ICMP.

              ping.png
              ping.png_thumb

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                so KOM is allowing all forms of icmp, here I only allow an echoreq (ie ping)..  But I do have a specific reject rule so that traceroute works to pfsense as well.

                allowping.png
                allowping.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • N
                  nischl
                  last edited by

                  How do you do that? I am researching this for 4 hours now but could not get any information on how to set the Icmp options

                  1 Reply Last reply Reply Quote 0
                  • pttP
                    ptt Rebel Alliance
                    last edited by

                    When you create the FW Rule:

                    Protocol = ICMP

                    ICMP type = Select/Choose one from the dropdown list

                    ICMP_Type.png
                    ICMP_Type.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • N
                      nischl
                      last edited by

                      thanks a lot, i didn't realize that the screen changes with the protocol selected

                      @thread_owner: sorry for hijacking your thread

                      1 Reply Last reply Reply Quote 0
                      • T
                        TomT
                        last edited by

                        Thanks for the replies.
                        I spoke to the owner of the addresses to see what they are, I've also added a rule to allow ICMP echoreq.

                        Thanks

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.