Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Should I Unblock ICMP on the WAN?

    Scheduled Pinned Locked Moved General pfSense Questions
    21 Posts 12 Posters 5.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by A Former User

      if I sent out an echo request most likely I would need an echo reply to pass in, isn't it ?
      the question is: how automatically generated outbound NAT can help me with this?

      P.S.
      or maybe there is a hidden set of rules comes into play
      ( not visible from our side of the fence... ) ?

      1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense
        last edited by

        I have been struggling with this ICMP. I know it is harmless traffic, mostly router gossip; however, I cannot stand it tapping on my WAN door ... so I drop them.

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        GertjanG JKnottJ 2 Replies Last reply Reply Quote 0
        • GertjanG
          Gertjan @NollipfSense
          last edited by

          @nollipfsense said in Should I Unblock ICMP on the WAN?:

          I cannot stand it tapping on my WAN door ... so I drop them.

          It's still tapping then, it's still there.
          Dropping just means you spend a minimal of CPU cycles on it: "pfSense" doesn't react == send something back - on its arrival.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          NollipfSenseN 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @NollipfSense
            last edited by

            @nollipfsense said in Should I Unblock ICMP on the WAN?:

            I have been struggling with this ICMP. I know it is harmless traffic, mostly router gossip; however, I cannot stand it tapping on my WAN door ... so I drop them.

            If you're running IPv6, you have to allow some in.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            NollipfSenseN 1 Reply Last reply Reply Quote 0
            • S
              slimypizza @tagit446
              last edited by

              @tagit446
              I wrote a heartbeat function on my external hosted site that will ping my pfsense router every few minutes through the WAN. If my router doesn’t respond then I get notified. So I have a rule that only allows ICMP (any) from the block of IP’s that my web host uses to ping me. Otherwise all other ICMP are blocked and I have not noticed any issues. I’m only using IPV4.

              1 Reply Last reply Reply Quote 0
              • AKEGECA
                AKEGEC @tagit446
                last edited by

                @tagit446 Some ICMP types are dangerous. But some are needed like

                • 3 Destination Unreachable
                • 8 ICMP Echo Request (Ping)
                • 11 Time Exceeded
                • 12 Parameter Problem

                But the authors of pfSense book advise you to allow any type ICMP. That is a NO NO!
                If you don't need it then just block it.

                1 Reply Last reply Reply Quote 0
                • NollipfSenseN
                  NollipfSense @Gertjan
                  last edited by

                  @gertjan said in Should I Unblock ICMP on the WAN?:

                  @nollipfsense said in Should I Unblock ICMP on the WAN?:

                  I cannot stand it tapping on my WAN door ... so I drop them.

                  It's still tapping then, it's still there.
                  Dropping just means you spend a minimal of CPU cycles on it: "pfSense" doesn't react == send something back - on its arrival.

                  Suricata drops them and don't notify me anymore ... not dropped at the firewall.

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  1 Reply Last reply Reply Quote 0
                  • NollipfSenseN
                    NollipfSense @JKnott
                    last edited by

                    @jknott said in Should I Unblock ICMP on the WAN?:

                    @nollipfsense said in Should I Unblock ICMP on the WAN?:

                    I have been struggling with this ICMP. I know it is harmless traffic, mostly router gossip; however, I cannot stand it tapping on my WAN door ... so I drop them.

                    If you're running IPv6, you have to allow some in.

                    No, that's the thing ... I need to get over my IPv6 shyness.

                    pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                    pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                    JKnottJ 1 Reply Last reply Reply Quote 0
                    • JKnottJ
                      JKnott @NollipfSense
                      last edited by

                      @nollipfsense

                      Does your ISP provide it? If not, you can get it via tunnel from he.net.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      1 Reply Last reply Reply Quote 0
                      • AKEGECA
                        AKEGEC @tagit446
                        last edited by

                        @tagit446 forgot to tell, don't forget to enable log for these rules.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.