Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IP Monitoring: Acceptable to Ping Public DNS Servers Every Second?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 6 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JSchenkJ
      JSchenk
      last edited by JSchenk

      While reading the Routing chapter in the pfSense book, I strolled upon Monitor IP, and this quote regarding WAN gateways, "Some popular choices include Google public DNS servers, or popular web sites such as Google or Yahoo." and this gem, "By default, the system will ping each gateway once per second to monitor latency and packet loss..."

      I don't want to do anything unneighborly; is it really OK to ping the snot out of public DNS servers? I don't want the internet hounds released on me.

      Old technology guy, new to wide-area networking.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        One tiny ping packet won't upset anyone, even once per second. I wouldn't worry about it. What I would worry about is whether you really want to use something that far away for your gateway monitor. We had a debate about this just a week or two ago. Some folks like to monitor some external site that's many hops away, like Google DNS. Others, like me, think it's better to monitor your actual gateway or 1-2 hops upstream.

        JSchenkJ 1 Reply Last reply Reply Quote 1
        • kiokomanK
          kiokoman LAYER 8
          last edited by

          no doubt that the answer from google is a courtesy
          if and when they will find ping an annoying matter they will just block it.
          until then use it

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          JSchenkJ 1 Reply Last reply Reply Quote 2
          • JSchenkJ
            JSchenk @KOM
            last edited by

            @KOM I searched the NetGate site for an answer before I posted this question, and came up empty. After you responded, I searched your posts and found this: https://forum.netgate.com/topic/146142/how-to-detect-a-cyber-attack (which I believe is the the thread to which you refer) Thank you.

            1 Reply Last reply Reply Quote 0
            • JSchenkJ
              JSchenk @kiokoman
              last edited by

              @kiokoman Thanks.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                The default pings from pfsense are 0 data in size.. I just ping the local gateway of pfsense.. This tells me have connectivity to the isp.. I see no point in pinging something out in the internet, especially some anycast IP that could be anywhere - so you could get wildly differing RTT..

                The only reason you might ping something upstream, if the local gateway for pfsense is onsite - and doesn't really tell you if actually connected to the ISP.. So you would pick something a hop or 2 past that.

                I had issue just awhile ago where I noticed I was seeing packet loss to my local gateway.. This tells me something between me and my isp is not good, if was pinging something upstream - it could be anything between me and that destination..

                Do whatever makes you feel better, but I concur a ping every second to some IP that answers ping and is such a major player as say googledns isn't going to be even noticed.. They must get 100's of thousands of them ;) All the time, what is the one of the first thing anyone ever pings when checking connectivity - 8.8.8.8 ;)

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                JSchenkJ 1 Reply Last reply Reply Quote 2
                • JSchenkJ
                  JSchenk @johnpoz
                  last edited by

                  @johnpoz Understood completely, Thanks.

                  1 Reply Last reply Reply Quote 0
                  • JeGrJ
                    JeGr LAYER 8 Moderator
                    last edited by

                    @johnpoz said in IP Monitoring: Acceptable to Ping Public DNS Servers Every Second?:

                    So you would pick something a hop or 2 past that.

                    Difficult to do that e.g. for german main ISP player German Telekom. Their ADSL/VDSL GW never responds to ping in the first place and the 2nd or third hop outof their net changes occasionally (based on dialed in users, packet load etc.) so to select a somewhat stable endpoint is a puzzle game and you can end up with an IP that moved away from your direct line of traceroute because they changed their routing again and your chosen hop isn't "your" hop anymore...

                    To cite you it's a real whack-a-mole game ;)

                    Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                    If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                    1 Reply Last reply Reply Quote 1
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      @JeGr said in IP Monitoring: Acceptable to Ping Public DNS Servers Every Second?:

                      Their ADSL/VDSL GW never responds to ping

                      Do they site a reason behind this? Are their gateways so overloaded they can't handle a few pings?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 1
                      • JeGrJ
                        JeGr LAYER 8 Moderator
                        last edited by

                        @johnpoz said in IP Monitoring: Acceptable to Ping Public DNS Servers Every Second?:

                        Do they site a reason behind this?

                        Nope, been that way for years (tempted to say decades). Just when having a look at a traceroute of a customers WAN going out to the web and your first hop is

                        * * * -
                        

                        you're like 90% sure already that this is a "Deutsche Telekom" DSL line - or some reseller. First hop on their PPPoE setup was never answering ICMP AFAIR.

                        Are their gateways so overloaded they can't handle a few pings?

                        Thinking more along the ways "we're doing it like we did it in decades! can't be wrong for 20+ years..." ;)

                        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                        1 Reply Last reply Reply Quote 1
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          I would wager that by now google, etc have a whole ICMP infrastructure set up and the DNS servers are not actually the ones responding to pings.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.