Is ICMP stateful?
-
If I allow all outbound ICMP, do I need to allow incoming ICMP for say Echo Reply in order to get a response?
-
No, you don't.
-
ICMP the protocol is not stateful, however, pf does keep state on ICMP in a timed fashion the same way it does for UDP (also stateless at the protocol level)
As dhatz mentioned, you don't have to worry about the replies in rules, the state table will handle that.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.