What are the minimum and maximum sizes of an ICMP packet?
ICMP, the Internet Control Message Protocol, is a protocol used to test the connectivity between hosts or networks. The popular 'ping' command derives from the ICMP protocol and is known as an 'echo' message, while the 'ping reply' is... the 'echo response' message. The protocol itself contains many different types of messages and their format is pretty standard.
The minimum size of any ICMP packet, or message, is much lower than the minimum Ethernet frame size on an Ethernet network, which is 64 bytes. Because of this imposed requirement, and that fact that almost all ICMP headers are only 20 bytes in length, the rest is additional overhead from the third and second OSI Layers. This overhead includes destination and source IP addresses, various IP flags and, lastly, the destination and source Mac address. These all together, along with a bit of padding that occurs, helps bring the total frame site to its minimum length, which as we said is 64 bytes.
Effectively, you could say that the smallest ICMP Packet is 64 bytes, while the largest size is usually found in the reply messages where the original IP and ICMP header is added to the reply, increasing its size to 76 bytes – under normal circumstances.
It's quite important to note that at this point it is possible to create an ICMP packet with a much larger size, and this is used today in flooding attempts, where a host is constantly bombarded with large ICMP packets, causing network problems to the host who will eventually drop offline! These attacks are well known as "ping floods" and are popular on IRC servers.
In closing, if you would like to find out detailed information about the ICMP structure, messages and other options the protocol supports, you can visit Firewall.cx where the protocol is covered in great detail.
Dig Deeper on Network Infrastructure
Related Q&A from Chris Partsenidis
A MAC address and an IP address each identify network devices, but they do the job at different levels. Explore the differences between the two and ... Continue Reading
A half-duplex transmission could be considered a one-way street between sender and receiver. Full-duplex, on the other hand, enables two-way traffic ... Continue Reading
SFP ports enable Gigabit switches to connect to a wide variety of fiber and Ethernet cables in order to extend switching functionality throughout the... Continue Reading