Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Should I Unblock ICMP on the WAN?

    Scheduled Pinned Locked Moved General pfSense Questions
    21 Posts 12 Posters 5.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      Yeah. Block bogons and RFC1918 only affects connections coming into WAN with a SOURCE ADDRESS in those ranges. That should never happen with actual internet traffic and if it does you probably want it blocked anyway which is why that feature exists in the first place.

      The only way that might happen is connections from the ISP device itself unless the firewall is inside your private network for whatever reason in which case you want to disable that feature.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • ?
        A Former User
        last edited by A Former User

        if I sent out an echo request most likely I would need an echo reply to pass in, isn't it ?
        the question is: how automatically generated outbound NAT can help me with this?

        P.S.
        or maybe there is a hidden set of rules comes into play
        ( not visible from our side of the fence... ) ?

        1 Reply Last reply Reply Quote 0
        • NollipfSenseN
          NollipfSense
          last edited by

          I have been struggling with this ICMP. I know it is harmless traffic, mostly router gossip; however, I cannot stand it tapping on my WAN door ... so I drop them.

          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

          GertjanG JKnottJ 2 Replies Last reply Reply Quote 0
          • GertjanG
            Gertjan @NollipfSense
            last edited by

            @nollipfsense said in Should I Unblock ICMP on the WAN?:

            I cannot stand it tapping on my WAN door ... so I drop them.

            It's still tapping then, it's still there.
            Dropping just means you spend a minimal of CPU cycles on it: "pfSense" doesn't react == send something back - on its arrival.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            NollipfSenseN 1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @NollipfSense
              last edited by

              @nollipfsense said in Should I Unblock ICMP on the WAN?:

              I have been struggling with this ICMP. I know it is harmless traffic, mostly router gossip; however, I cannot stand it tapping on my WAN door ... so I drop them.

              If you're running IPv6, you have to allow some in.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              NollipfSenseN 1 Reply Last reply Reply Quote 0
              • S
                slimypizza @tagit446
                last edited by

                @tagit446
                I wrote a heartbeat function on my external hosted site that will ping my pfsense router every few minutes through the WAN. If my router doesn’t respond then I get notified. So I have a rule that only allows ICMP (any) from the block of IP’s that my web host uses to ping me. Otherwise all other ICMP are blocked and I have not noticed any issues. I’m only using IPV4.

                1 Reply Last reply Reply Quote 0
                • AKEGECA
                  AKEGEC @tagit446
                  last edited by

                  @tagit446 Some ICMP types are dangerous. But some are needed like

                  • 3 Destination Unreachable
                  • 8 ICMP Echo Request (Ping)
                  • 11 Time Exceeded
                  • 12 Parameter Problem

                  But the authors of pfSense book advise you to allow any type ICMP. That is a NO NO!
                  If you don't need it then just block it.

                  1 Reply Last reply Reply Quote 0
                  • NollipfSenseN
                    NollipfSense @Gertjan
                    last edited by

                    @gertjan said in Should I Unblock ICMP on the WAN?:

                    @nollipfsense said in Should I Unblock ICMP on the WAN?:

                    I cannot stand it tapping on my WAN door ... so I drop them.

                    It's still tapping then, it's still there.
                    Dropping just means you spend a minimal of CPU cycles on it: "pfSense" doesn't react == send something back - on its arrival.

                    Suricata drops them and don't notify me anymore ... not dropped at the firewall.

                    pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                    pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                    1 Reply Last reply Reply Quote 0
                    • NollipfSenseN
                      NollipfSense @JKnott
                      last edited by

                      @jknott said in Should I Unblock ICMP on the WAN?:

                      @nollipfsense said in Should I Unblock ICMP on the WAN?:

                      I have been struggling with this ICMP. I know it is harmless traffic, mostly router gossip; however, I cannot stand it tapping on my WAN door ... so I drop them.

                      If you're running IPv6, you have to allow some in.

                      No, that's the thing ... I need to get over my IPv6 shyness.

                      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                      JKnottJ 1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott @NollipfSense
                        last edited by

                        @nollipfsense

                        Does your ISP provide it? If not, you can get it via tunnel from he.net.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        1 Reply Last reply Reply Quote 0
                        • AKEGECA
                          AKEGEC @tagit446
                          last edited by

                          @tagit446 forgot to tell, don't forget to enable log for these rules.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.