What is ICMP?
ICMP is a small helper message system on the internet. The best known use is ping. When you ping a server, you ask, "Are you there?" The server answers, "Yes." These messages are ICMP requests.
Ping is useful. But some people turn it off. It makes the server a little harder to spot. It can also cut down floods of junk ping traffic.
Warning: Blocking ping can confuse monitoring tools. They may say your server is down when it is not. Some support checks use ping too. Take a note of your current firewall settings before you change anything.
Method 1: Use a command
- Log in to your server over SSH as root. SSH lets you type commands on the server from far away.
- Check that ping works now. From another computer, run
ping YOUR-SERVER-IP. - Run this command on the server.
This drops all incoming ping requests. Drop means the server ignores them.iptables -A INPUT -p icmp --icmp-type echo-request -j DROP - Ping the server again from the other computer. It should time out.
This change vanishes after a reboot. To keep it, add the rule to your firewall tool. If your server uses CSF, the next method is better.
Method 2: Use CSF
CSF is a firewall add-on often used with cPanel. Your server may or may not have it.
- Log in to WHM.
- Search for ConfigServer Security & Firewall.
- Click Firewall Configuration.
- Find the setting called
ICMP_IN. - Set it to
0. This blocks incoming ping. - Click Change at the bottom, then Restart csf+lfd.
How to turn ping back on
- For the command method, run
This removes the rule.iptables -D INPUT -p icmp --icmp-type echo-request -j DROP - For CSF, set
ICMP_INback to1and restart.
Quick recap
- ICMP carries ping messages.
- You can block them with an iptables rule or with CSF.
- Monitoring tools may report a false "down" status.
- Remove the rule to turn ping back on.