icmp port numbers


Can any one explain me the ports numbers used for icmp both for echo request and reply

Any standard piece of code for blocking echo request and echo reply ;please help with the code for both router and pix;

Please help with the port for snmp also

JFrederick29
i_t
access-list 101 deny udp any any eq snmp
access-list 101 deny icmp any any

i don't think echo uses a port number because it is beneath tcp
phoenix26Author
Hi ,

Thanks for your suggestion.

But i beileve there is some way for blocking icmp echo request and echo reply ?any suggestions on coding
atlas_shudderedSr. Network Engineer
icmp doesn't use port numbers as noted above.

for your rtr you'll need to post the following lines in your acl:

ip access-list ext XXXX
permit icmp {source ip} {source mask}/{any} {destination ip} {destination mask}/{any} echo
permit icmp {source ip} {source mask}/{any} {destination ip} {destination mask}/{any} echo reply

for the pix you can use the same format, difference being that if you are trying to ping from outside to inside you will need to set up a translation set.

Hope it helps.

