ICMP Payload
ICMP error messages are sent when the kernel detects an error condition while processing an ingress IP packet. All ICMP error types include the same information in the ICMP payload : the IP header of the IP packet that triggered the transmission of the ICMP message, plus a portion of the IP payload. The resulting IP packet must not exceed 576 bytes in size, including the outer IP header and the ICMP header. (This last rule is stated in RFC 1812, section 4.3.2.3, which updates the header definitions of RFC 792. According to the older RFC 792, the ICMP payload needs to include only the original IP header plus 64 bits of the original transport header.)
Figure 25-2 shows an example of what
an ICMP_FRAG_NEEDED error message looks like according
to RFC 792. Figure 25-2(a) is the
fragment that triggered the transmission of the ICMP message, and Figure 25-2(b) is the ICMP message. Note
that the ICMP payload includes the original IP header and a piece of the transport header,
too. Linux is compliant with RFC 1812, and therefore includes the extra block shown in
Figure 25-2(a), up to a size of 576
bytes.
The protocol field of the original IP header will be used by the target of the ICMP message to identify the right transport protocol (TCP in the example) and a portion of the transport header in the ICMP payload (which includes source and destination port numbers) will allow the same target host to identify a local socket. Thus, the target host will have some help tracking down ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access