λ³Έλ¬Έ λ°”λ‘œκ°€κΈ°

μ—¬λŸ¬κ°€μ§€/μ •λ³΄λ³΄μ•ˆ 정리

[μ •λ³΄λ³΄μ•ˆ 정리] λ„€νŠΈμ›Œν¬ - ICMP ν”„λ‘œν† μ½œ

728x90

3계측 IP ν”„λ‘œν† μ½œμ€ μ‹ λ’°ν•  수 μ—†λŠ” ν”„λ‘œν† μ½œ.

μ „μ†‘μƒνƒœμ— λŒ€ν•œ 관리가 이루어지지 μ•ŠλŠ” 단점을 λ³΄μ™„ν•˜κΈ° μœ„ν•œ ν”„λ‘œν† μ½œμ΄ ICMP ν”„λ‘œν† μ½œ

 

*ICMP ν”„λ‘œν† μ½œ

: IP νŒ¨ν‚· 전솑 쀑 μ—λŸ¬ λ°œμƒ μ‹œ μ—λŸ¬ λ°œμƒ 원인을 μ•Œλ €μ£Όκ±°λ‚˜ λ„€νŠΈμ›Œν¬ μƒνƒœλ₯Ό μ§„λ‹¨ν•΄μ£ΌλŠ” κΈ°λŠ₯ 제곡

-Error-Reporting Message : 전솑 쀑 였λ₯˜ λ°œμƒ μ‹œ μ—λŸ¬λ©”μ‹œμ§€ 생성

-Query Message : λ„€νŠΈμ›Œν¬ μƒνƒœ 진단을 μœ„ν•œ 쿼리 μš”μ²­ 및 응닡 λ©”μ‹œμ§€

 


 

*ICMP ν”„λ‘œν† μ½œ ꡬ쑰

https://info.support.huawei.com/info-finder/encyclopedia/en/ICMP.html

- Type(8bits) : ICMP λ©”μ‹œμ§€ μœ ν˜•/μš©λ„

-Code(8bits) : Type μ„ΈλΆ€ λ‚΄μš©

-Checksum(16bits) : ICMP λ©”μ‹œμ§€ 였λ₯˜ 검사 κ°’

-Rest of the header : Typeκ³Ό Code에 따라 μΆ”κ°€λ˜λŠ” 헀더

-Data section : 데이터가 μœ„μΉ˜ν•˜λŠ” μ˜μ—­

 


 

*ICMP Error-Reporting λ©”μ‹œμ§€

-Destination Unreachable(Type 3) : ν•΄λ‹Ή λͺ©μ μ§€ 도달 ν•  수 μ—†μŒ

(1) Code 1(Host Unreachable) : μ΅œμ’… λ‹¨κ³„μ˜ λΌμš°ν„°κ°€ λͺ©μ μ§€ 호슀트둜 νŒ¨ν‚· 전솑 μ‹€νŒ¨

(2) Code 2(Protocol Unreachable) :  λͺ©μ μ§€ ν˜ΈμŠ€νŠΈμ—μ„œ νŠΉμ • ν”„λ‘œν† μ½œμ„ μ‚¬μš©ν•  수 μ—†λŠ” 경우

(3) Code 3(Port Unreachable) : λͺ©μ μ§€ ν˜ΈμŠ€νŠΈμ— ν•΄λ‹Ή UDP ν¬νŠΈκ°€ μ—΄λ €μžˆμ§€ μ•Šμ€ 경우,

TCP 경우 ν¬νŠΈκ°€ μ—΄λ €μžˆμ§€ μ•ŠμœΌλ©΄ TCP RST νŒ¨ν‚· λ°˜ν™˜

(4) Code 4(Fragmentation needed and don't fragment was set) : IP νŒ¨ν‚· λ‹¨νŽΈν™”κ°€

λ°˜λ“œμ‹œ ν•„μš”ν•˜λ‚˜ IP ν—€λ”μ˜ Don't fragment ν”Œλž˜κ·Έκ°€ μ„€μ •λ˜μ–΄ λ‹¨νŽΈν™”κ°€ λΆˆκ°€λŠ₯ν•œ 경우

 

-Redirection(Type 5) : λΌμš°νŒ… κ²½λ‘œκ°€ 잘λͺ»λ˜μ–΄ μƒˆλ‘œμš΄ 경둜λ₯Ό 이전 κ²½μœ μ§€ λ˜λŠ” ν˜ΈμŠ€νŠΈμ—κ²Œ μ•Œλ €μ£ΌλŠ” λ©”μ‹œμ§€

(1) ICMP Redirect 곡격에 μ‚¬μš©

 

-Time Exceeded(Type 11) : νƒ€μž„μ•„μ›ƒμ΄ λ°œμƒν•˜μ—¬ IP νŒ¨ν‚· 폐기

(1) Code 0(Time To Live exceeded in Transit) : IP νŒ¨ν‚·μ΄ μ΅œμ’… λͺ©μ μ§€ λ„λ‹¬ν•˜κΈ° 전에 TTL 값이 0이 λ˜μ–΄ 폐기

(2) Code 1(Fragment reassembly time exceeded) : IP νŒ¨ν‚· μž¬μ‘°ν•© κ³Όμ •μ—μ„œ νƒ€μž„μ•„μ›ƒ

 


 

*ICMP Query λ©”μ‹œμ§€

-Echo Request(Type 8) and Reply(Type 0)

: ping μœ ν‹Έλ¦¬ν‹° ν”„λ‘œκ·Έλž¨μ— μ‚¬μš©λ˜λŠ” λ©”μ‹œμ§€. 쒅단 λ…Έλ“œκ°„μ— λ„€νŠΈμ›Œν¬ 호슀트 μƒνƒœμ§„λ‹¨ λͺ©μ 

 


 

*ICMP λ¦¬λ‹€μ΄λ ‰νŠΈ(Redirect) 곡격

: ICMP Redirection λ©”μ‹œμ§€(Type 5)λ₯Ό μ΄μš©ν•΄ νŒ¨ν‚· 경둜λ₯Ό μ•…μ˜μ μœΌλ‘œ μž¬μ„€μ •ν•˜λŠ” 곡격.

ICMP Redirection λ©”μ‹œμ§€λ₯Ό μˆ˜μ‹ ν•œ ν˜ΈμŠ€νŠΈλŠ” μžμ‹ μ˜ λΌμš°νŒ… ν…Œμ΄λΈ”μ— νŠΉμ • λͺ©μ μ§€λ‘œ λ‚˜κ°€λŠ” gateway μ£Όμ†Œλ₯Ό λ³€κ²½ν•˜λŠ”λ°

κ³΅κ²©μžλŠ” 이λ₯Ό μ•…μš©ν•˜μ—¬ μžμ‹ μ΄ μ›ν•˜λŠ” ν˜•νƒœμ˜ ICMP Redirection λ©”μ‹œμ§€λ₯Ό λ§Œλ“€μ–΄ νŠΉμ • λͺ©μ μ§€λ‘œ κ°€λŠ” νŒ¨ν‚·μ„ 곡격자둜 ν–₯ν•˜λ„λ‘ 함.

 

-ARP Redirectμ™€μ˜ 차이점

(1) ARP Redirect : ν¬μƒμžμ˜ ARP Cache Table λ³€μ‘°ν•˜μ—¬ μŠ€λ‹ˆν•‘

(2) ICMP Redirect : ν¬μƒμžμ˜ λΌμš°νŒ… ν…Œμ΄λΈ” λ³€μ‘°ν•˜μ—¬ μŠ€λ‹ˆν•‘

 

-λŒ€μ‘λ°©λ²•

(1) ICMP Redirection λ©”μ‹œμ§€μ— μ˜ν•΄ λΌμš°νŒ… ν…Œμ΄λΈ”μ΄ λ³€κ²½λ˜μ§€ μ•Šλ„λ‘ Redirect μ˜΅μ…˜ ν•΄μ œ

#sysctl -w net.ipv4.conf.all.accept_redirects=0