6.3 2000 Series—ICMP Signatures
6.3.5 ICMP error message signatures
The following are ICMP Error Message signatures:
  • 2001—Unreachable (severity 1, information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 3 (Host Unreachable). ICMP Host Unreachable datagrams may be used to bypass packet filter security policies as they are rarely filtered in either incoming or outgoing traffic. May be used to perform DoS attacks.
  • 2002—Source Quench (severity 1, DoS/information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 4 (Source Quench). ICMP Source Quench datagrams may be used to bypass packet filter security policies as they are rarely filtered in either incoming or outgoing traffic. May be used to perform DoS attacks. No known exploits incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 2003—Redirect (severity 1, information): This signature is triggered when a IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 5 (Redirect). ICMP Redirects may be used to facilitate system access attempts. No known exploits incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 2005—Time Exceeded (severity 1, DoS/information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 11 (Time Exceeded for a Datagram). ICMP Time Exceeded datagrams may be used to bypass packet filter security policies as they are rarely filtered in either incoming or outgoing traffic. May be used to perform DoS attacks. No known exploits incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 2006—Parameter Problem (severity 1, information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 12 (Parameter Problem on Datagram). ICMP Parameter Problem datagrams may be used to bypass packet filter security policies as they are rarely filtered in either incoming or outgoing traffic. May be used to perform DoS attacks. No known exploits incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.