ICMP

ICMP

ICMP
ICMP
2024-08-20 18:20:07 - last edited 2024-08-21 01:03:44
Model: ER7212PC  
Hardware Version: V1
Firmware Version: 1.2.0 Build 20240716 Rel.80083

I am being plagued by WAN ping attacks every 10 minutes filling the error log constantly. These are from my SIP service provider's data centres. They say I need to disable ICMP in my firewall, but I can't see any option to disable it, only set a timeout state.

  0      
  0      
#1
Options
1 Accepted Solution
Re:ICMP-Solution
2024-08-21 01:03:40 - last edited 2024-08-21 01:03:44

Hi @AlanCBC 

Thanks for posting in our business forum.

IP scans are very common. Sometimes it is not an actual attack but a scan.

The ISP, your local government, or the national department may scan the network in your region. They may use the results for a security improvement.

There are also private scans from hackers and average people. This does not mean you are in danger. The block has been effective as long as you see the logs.

Disabling the ICMP would make your router stop responding to the ICMP tests. You cannot ping your public IP address as well. Note that.

Understanding TCP/UDP and How Omada Firewall Protects Your Network from Attacks

 

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
2 Reply
Re:ICMP-Solution
2024-08-21 01:03:40 - last edited 2024-08-21 01:03:44

Hi @AlanCBC 

Thanks for posting in our business forum.

IP scans are very common. Sometimes it is not an actual attack but a scan.

The ISP, your local government, or the national department may scan the network in your region. They may use the results for a security improvement.

There are also private scans from hackers and average people. This does not mean you are in danger. The block has been effective as long as you see the logs.

Disabling the ICMP would make your router stop responding to the ICMP tests. You cannot ping your public IP address as well. Note that.

Understanding TCP/UDP and How Omada Firewall Protects Your Network from Attacks

 

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
Re:ICMP
2024-08-21 07:45:36

  @Clive_A 

Thanks for that. I know they are only scans from my sip service provider and not attacks. It was that they just fill up the log resulting in numerous emails to myself.

I already had Block Large Ping and Ping from WAN set but seemed to make no difference.

However in the related articles I found a post from UlfLarsen that you replied to last year that did not show up when I searched for related articles before I posted this. This seems to offer my solution.

  1  
  1  
#3
Options