# ICMP Redirect on Cisco IOS

**URL:** https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247
**Category:** Lessons Discussion
**Created:** [December 29, 2016, 5:50pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247 "2016-12-29T17:50:34Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 29, 2016, 5:50pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/1 "2016-12-29T17:50:34Z")

</div>

This topic is to discuss the following lesson:

[https://networklessons.com/cisco/ccie-enterprise-infrastructureicmp-redirect-on-cisco-ios/](https://networklessons.com/cisco/ccie-enterprise-infrastructureicmp-redirect-on-cisco-ios/)

---

<div class="post-metadata">

### Author: ![talk2seeni](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/t/8baadc/32.png) [@talk2seeni](https://forum.networklessons.com/u/talk2seeni)
#### Post date: [June 18, 2015, 5:01pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/2 "2015-06-18T17:01:53Z")

</div>

Hi Rene,  
How to disable the ip redirect (receive) in Router acting as a host?

Thanks ,  
Srini

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [June 19, 2015, 4:35pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/3 "2015-06-19T16:35:17Z")

</div>

Hi Srini,

Hmm good question, I’m not sure if there is a command for it to disable this. You might be able to filter the incoming ICMP redirect message with an access-list, that could do the trick.

This is an exception situation btw, IP routing has to be disabled on the router which is not a common thing to do.

Rene

---

<div class="post-metadata">

### Author: ![talk2seeni](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/t/8baadc/32.png) [@talk2seeni](https://forum.networklessons.com/u/talk2seeni)
#### Post date: [June 19, 2015, 6:21pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/4 "2015-06-19T18:21:52Z")

</div>

Thanks Rene.

---

<div class="post-metadata">

### Author: ![wdavis84](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/w/7ba0ec/32.png) [@wdavis84](https://forum.networklessons.com/u/wdavis84)
#### Post date: [January 14, 2016, 9:36am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/5 "2016-01-14T09:36:05Z")

</div>

Hi Rene,

The IP redirect only redirect ICMP? Any other protocol will redirect other than this?

Davis

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [January 14, 2016, 9:51am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/6 "2016-01-14T09:51:51Z")

</div>

Hi Davis,

When you receive an ICMP redirect then it will apply to all IPv4 traffic.

Rene

---

<div class="post-metadata">

### Author: ![wdavis84](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/w/7ba0ec/32.png) [@wdavis84](https://forum.networklessons.com/u/wdavis84)
#### Post date: [January 15, 2016, 2:14am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/7 "2016-01-15T02:14:43Z")

</div>

Got it. Thanks Rene.

Davis

---

<div class="post-metadata">

### Author: ![Zaman.rubd](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/z/45deac/32.png) [@Zaman.rubd](https://forum.networklessons.com/u/Zaman.rubd)
#### Post date: [May 31, 2016, 8:47am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/8 "2016-05-31T08:47:56Z")

</div>

Thanks Rene. You have got 100 out of 100 .So Normally we will keep Disable ICMP redirect as its has security vulnerability but enable it when Meet the criteria below only :

1.The IP packet should be received and transmitted on the same interface.  
2.The source IP address of the incoming packet should be on the same subnet as the new next hop IP address.

Please correct me if I am wrong 🙂

br//  
zaman

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [May 31, 2016, 9:20pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/9 "2016-05-31T21:20:28Z")

</div>

Hi Zaman,

It’s best to disable ICMP redirect completely. This example is great to demonstrate it but it has a design issue. The hosts should use R2 as their default gateway, you won’t need ICMP redirects then 🙂

Rene

---

<div class="post-metadata">

### Author: ![Networklessions](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/n/ed655f/32.png) [@Networklessions](https://forum.networklessons.com/u/Networklessions)
#### Post date: [July 17, 2017, 6:41pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/10 "2017-07-17T18:41:56Z")

</div>

Hi Sir,

The line " R2 only has a static route for 3.3.3.3 with R2 as its next hop" but the conf shows 23.3 as next hop then it must be R3

Or R2 having next hop as R2 I m confused. Can you explain here

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 18, 2017, 7:06am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/11 "2017-07-18T07:06:02Z")

</div>

Hi Subbu,

This was a typo, it should be R3. Just fixed it, thanks!

---

<div class="post-metadata">

### Author: ![azmuddincisco](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/a/a87d85/32.png) [@azmuddincisco](https://forum.networklessons.com/u/azmuddincisco)
#### Post date: [September 11, 2018, 2:18am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/12 "2018-09-11T02:18:47Z")

</div>

Hello Rene,  
I have a question and I am going to use the below diagram as a reference for my question.

 ![image](https://cdn-forum.networklessons.com/uploads/default/original/2X/d/da6a4b13219c359e7ae50cde9c02b4b622ad3b05.png)

From this switch when I was trying to reach 10.10.20.20, I was not able to reach it. However, other IP addresses from the same subnet such as 10.10.20.1 or 10.10.20.50 is reachable from the switch.  
After doing some research, I found this:

```
Switch#show ip redirects
Default gateway is 192.168.115.10

Host Gateway Last Use Total Uses Interface
10.10.20.20 192.168.115.1 0:00 4912 Vlan20

```

Clearing the redirect cache resolved the issue and now 10.10.20.20 is reachable from the switch.

```
Switch#clear ip redirect
Switch#show ip redirects
Default gateway is 192.168.115.10

Host Gateway Last Use Total Uses Interface
ICMP redirect cache is empty

```

Would you please explain why?

Thanks in advance.

Best Regards,  
Azm Uddin

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [September 14, 2018, 6:13am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/13 "2018-09-14T06:13:23Z")

</div>

Hello Azm

To understand why this happened, it’s first important to understand what IP Redirects are and how they work. IP Redirects are ICMP messages that are sent by routers that inform hosts of more appropriate gateways to use to get to a destination. The following documentation explains it excellently, however I will summarise below:

> **[When Are ICMP Redirects Sent](https://www.cisco.com/c/en/us/support/docs/ip/routing-information-protocol-rip/13714-43.html)**
>
> This document discusses ICMP redirects and when redirects happen in a network.

Take a look at the following topology:

 ![image](https://cdn-forum.networklessons.com/uploads/default/original/2X/c/ca0d1e846a88434b77fa2bd662332931daf1e27d.png)  
First of all, notice that R1, R2 and Host H are all on the same subnet. Host H sends information to the remote branch office host. Host H is configured to use R1 as the default gateway. R1 examines its routing table and sees that the next hop should be R2. It also realises that Host H and the next hop are on the same subnet, so it sends an ICMP redirect to Host H informing it that it should send all future packets with a destination of the remote branch office host to R2. This entry is added to the IP redirect cache of the host.

Now, if the network topology changes such that the remote branch host can only be reached via R1 and no longer via R2, the IP redirect entry that has been provided will tell host H to go via R2 which is no longer valid, and the communication will fail.

This is what I believe has happened in your case. 10.10.20.20 was reachable at some point via the firewall at 192.168.115.10 and that was actually a better gateway to use for that destination so the switch was informed by an ICMP redirect message from the router that 192.168.115.1 is a better gateway choice and the switch maintained that info in its IP redirect cache. Your topology then changed somehow and 10.10.20.20 was no longer accessible via the firewall, however, the IP redirect was still valid and was trying to send the packets that way. Once you cleared the IP redirect list, the configured default gateway was being used and connectivity was restored.

I hope this as been helpful!

Laz

---

<div class="post-metadata">

### Author: ![sutandrac1](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/ac91a4/32.png) [@sutandrac1](https://forum.networklessons.com/u/sutandrac1)
#### Post date: [July 28, 2019, 11:27am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/14 "2019-07-28T11:27:26Z")

</div>

Hi Rene ,

Just as always it is so useful to read through your thorough workouts.  
So I think there is still another typo to be corrected 😄  
when the linux host is pinging 3.3.3.3 , in the message for the ICMP redirect new Nexthop should it not be 192.168.12.2 ?

sorry if I am mistaken .

---

<div class="post-metadata">

### Author: ![sutandrac1](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/ac91a4/32.png) [@sutandrac1](https://forum.networklessons.com/u/sutandrac1)
#### Post date: [July 28, 2019, 3:29pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/15 "2019-07-28T15:29:58Z")

</div>

Also I tried to reproduce the same on the on GNS3 3725 platform with IOS c3725-adventerprisek9-mz.124-15.T7.image…and I configured static route on all the routers . So on the default gateway I did have the static route

```
PC-1> ping 3.3.3.3
3.3.3.3 icmp_seq=1 timeout
3.3.3.3 icmp_seq=2 timeout
84 bytes from 3.3.3.3 icmp_seq=3 ttl=62 time=59.972 ms
84 bytes from 3.3.3.3 icmp_seq=4 ttl=62 time=47.914 ms
84 bytes from 3.3.3.3 icmp_seq=5 ttl=62 time=50.978 ms

PC-1> trace 3.3.3.3
trace to 3.3.3.3, 8 hops max, press Ctrl+C to stop
 1 192.168.12.1 4.952 ms 9.991 ms 9.042 ms
 2 3.3.3.3 9.929 ms 21.004 ms 10.019 ms
 3 192.168.12.2 8.982 ms 31.034 ms 9.045 ms
 4 192.168.23.1 21.917 ms

```

the autu secure feature is there and is not in effect so ip redirect is not disabled.

My question is since icmp part of ip if ip redirect is not disabled by default then PC1 should get the message right ? But then it is no proper host …a simulated one.  
And not sure why the 2nd hop is 3.3.3.3 on my traceroute from the pc1 ?  
The ip route on R1 is as follows

```
R1(config-if)#do show ip route
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route

Gateway of last resort is 1.1.1.2 to network 0.0.0.0

C 192.168.12.0/24 is directly connected, FastEthernet0/0
     1.0.0.0/30 is subnetted, 1 subnets
C 1.1.1.0 is directly connected, Loopback0
     3.0.0.0/32 is subnetted, 1 subnets
S 3.3.3.3 [1/0] via 192.168.12.2
S* 0.0.0.0/0 [1/0] via 1.1.1.2
R1(config-if)#

```

I have found that ‘no ip icmp redirect’ is available on the router for use.

It will be good to get your feedback please ?

Kind regards,

Sutandra

---

<div class="post-metadata">

### Author: ![sutandrac1](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/ac91a4/32.png) [@sutandrac1](https://forum.networklessons.com/u/sutandrac1)
#### Post date: [July 28, 2019, 7:03pm UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/16 "2019-07-28T19:03:41Z")

</div>

Also is multicast routing techniques a kind of source routing as ICMP redirect messages if enabled do not work if IP packets use source routing …trying to get what is that

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [July 31, 2019, 9:42am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/17 "2019-07-31T09:42:51Z")

</div>

Hello Sutandra

Yes you are correct, I’ll let Rene know about that…

Laz

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [July 31, 2019, 10:25am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/18 "2019-07-31T10:25:08Z")

</div>

Hello Sutandra

> [@sutandrac1](#):
>
> My question is since icmp part of ip if ip redirect is not disabled by default then PC1 should get the message right ?

Yes it will get the message. It doesn’t matter that the “host” is actually a router. The behaviour of the ICMP protocol will be the same for either a PC or a router.

> [@sutandrac1](#):
>
> And not sure why the 2nd hop is 3.3.3.3 on my traceroute from the pc1 ?

Hmm, that is quite interesting. My hunch is that traceroute sends the first ICMP packet with a TTL of 1 to the gateway of 192.168.12.1, which is the first response we see. Then R1 sends a redirect back to the host informing it of the “better” gateway. The host sends an ICMP packet with a maximum TTL with the new gateway to see if it gets a response which it does. It then proceeds to continue the trace using increasing TTLs to R2 and R3.

This is just a hunch, but a wireshark trace of something like this would be very beneficial… I suggest you give it a try and share your results.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [July 31, 2019, 10:27am UTC](https://forum.networklessons.com/t/icmp-redirect-on-cisco-ios/1247/19 "2019-07-31T10:27:26Z")

</div>

Hello Sutandra

I’m not sure I understand completely, but multicast routing is something somewhat independent of ICMP redirect. For more information about multicast routing, take a look at the following lesson:

> **[Multicast Routing](https://networklessons.com/multicast/multicast-routing)**
>
> This lesson explains the basics of multicast routing, dense mode, sparse mode, the RPF check and multicast traffic scoping.

I hope this has been helpful!

Laz
