Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    block outbound ICMP or not?

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 454 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • beerguzzleB Online
      beerguzzle
      last edited by

      My setup: Netgate 1100, pfsense+ version 23.05.1.

      I have a rule that allows outbound an explicit pass on the LAN and OPT interfaces for ICMP, like so:

      Screenshot 2023-11-03 at 9.39.50 AM.png

      I don't do NATing, VPNs or anything else exotic. Logging for this rule shows outbound connections from various LAN/OPT devices to places like (mostly) cloudfront. Are these connections good, bad, harmless, nefarious? Is this rule a bright idea or a bad move?

      Netgate 1100 and Netgate 2100, latest pfsense+ version

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ Online
        JKnott @beerguzzle
        last edited by

        @beerguzzle

        What do you expect to accomplish by blocking it? ICMP is used for a lot of things and on IPv6 it's essential.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        beerguzzleB 1 Reply Last reply Reply Quote 0
        • beerguzzleB Online
          beerguzzle @JKnott
          last edited by

          @JKnott My explicit pass rule has been there for a while, but I turned on logging the other day and started noticing outbound traffic beyond my own "traceroute -P icmp" work. Hence my question... I didn't know that IPv6 relied on it.

          Netgate 1100 and Netgate 2100, latest pfsense+ version

          1 Reply Last reply Reply Quote 0
          • U Offline
            Uglybrian
            last edited by

            Hi- from the Netgate Doc; https://docs.netgate.com/pfsense/en/latest/firewall/configure.html

            1 Reply Last reply Reply Quote 0
            • beerguzzleB Online
              beerguzzle
              last edited by

              Thanks for pointing me to the ICMP part of the doc, I should have looked there. Another dumb question put to rest. I'll turn off logging for my pass rule (like it was) and leave things alone. Thank you both.

              Netgate 1100 and Netgate 2100, latest pfsense+ version

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.