ICMP Types and Codes and Flow Records

Flow records also record ICMP types and codes, displaying them as destination port numbers. I'll review ICMP types and codes first and then discuss how flow records portray them.

Types and Codes in ICMP

Many people mentally pour the different ICMP requests into one large bucket and get by on generalizations such as "ICMP is ping." Although this might be fine for average users, you're not an average user, and you need a deeper understanding of ICMP to manage a network.

An ICMP type is a general class of ICMP request, such as ping requests and ping replies. Other ICMP types include messages such as "host unreachable," routing advertisements, traceroute requests, routing redirects, and so on. Some ICMP types prompt ...

Get Network Flow Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.