Overview
Internet Control Message Protocol (ICMP) carries diagnostic and error messages that explain why traffic fails or slows. From a PCAP/PCAPNG you can verify reachability (echo/ping), locate routing loops (Time Exceeded), confirm filtering/policy (Destination Unreachable variants), and troubleshoot Path MTU Discovery (Packet Too Big in IPv6 or Fragmentation Needed in IPv4). ICMP is also rate-limited and sometimes blocked—patterns that the analyzer highlights so you don’t misread the absence of replies.
- What you’ll see: type/code breakdowns, echo request/reply timing, Time Exceeded bursts, Unreachable causes, Packet Too Big/Frag Needed for PMTUD, source hops
- Best for: NOC troubleshooting, SOC triage, incident response, performance analysis
- Works with: IP layer symptoms that affect TCP/UDP, DNS, HTTP, and TLS performance
What to look for
- Reachability: echo/ping loss or high RTT → congestion, filtering, or rate-limits
- Routing loops: bursts of Time Exceeded from the same hop → misrouting or IGP changes
- Filtering/policy: Destination Unreachable (admin prohibited, port unreachable) → firewall/NAC
- PMTUD failures: IPv6 Packet Too Big or IPv4 Frag Needed missing → MTU black hole
- Asymmetry: replies from unexpected ASNs/hops; different forward/return paths
- Rate-limits: thinning reply cadence during probe bursts → normal throttling vs real loss
Capture tips
- Capture near the edge hop (gateway/WAN) to see genuine ICMP errors and who sent them.
- Include both ICMP (IPv4) and ICMPv6; IPv6 relies heavily on ICMP for ND and PMTUD.
- Run controlled probes (ping/traceroute with varying sizes) while capturing to reproduce the issue.
- Avoid NIC offloads (LRO/GRO/TSO) to keep headers intact for type/code analysis.
- Keep a focused time window so you fit within the 10 MB demo limit.
Example walkthrough
- Filter to ICMP/ICMPv6; optionally add hosts or networks of interest.
- Check type/code counts: Echo (8/0), Destination Unreachable (3), Time Exceeded (11); for IPv6, Packet Too Big (2).
- Correlate ICMP errors with affected TCP/UDP flows to see which apps are impacted.
- Inspect hop IPs that generated errors to localize the failing segment.
- Run a larger-payload ping during capture to confirm PMTUD symptoms (expect Packet Too Big/Frag Needed).
- Export a short report with timelines and hop attributions for the ticket.
ICMP FAQ
Echo/ping reachability, Destination Unreachable (policy/port), Time Exceeded for routing loops, and Path MTU Discovery failures via Packet Too Big/Frag Needed. These messages pinpoint where the path breaks.
PMTUD needs ICMP errors to work. When blocked, large packets may be dropped silently—creating MTU black holes and intermittent failures.
Host firewalls return specific unreachables or ignore echo. Network faults show Time Exceeded or admin prohibited from intermediate hops. Correlate ICMP sources and hop numbers.
ICMPv6 carries Neighbor Discovery and Packet Too Big; filtering it too aggressively breaks IPv6 quickly. Watch key types/codes and ND traffic together.
Routers/hosts throttle ICMP. Sparse replies during probe bursts can be normal; look for thinning cadence rather than assuming loss. The analyzer marks likely throttling.