Re: Login AD and ICMP



icmp is used to detect whether a link is slow or fast, for such pieces of AD
as group policy ... if it doesn't get a response in a certain time frame
(It suspects it is to slow) group policy application is not attempted.


For Active Directory to function correctly through a firewall, the Internet
Control Message Protocol (ICMP) protocol must be allowed through the
firewall from the clients to the domain controllers so that the clients can
receive Group Policy information.

ICMP is used to determine whether the link is a slow link or a fast link.
ICMP is a legitimate protocol that Active Directory uses for Group Policy
detection and for Maximum Transfer Unit (MTU) detection. The Windows
Redirector also uses ICMP to verify that a server IP is resolved by the DNS
service before a connection is made.

If you want to minimize ICMP traffic, you can use the following sample
firewall rule:
<any> ICMP -> DC IP addr = allow

From
http://support.microsoft.com/kb/179442

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"BZP" <p.audonnet@xxxxxxxxx> wrote in message
news:1188580525.448952.19570@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello,

I remarked that AD Cleint ping their DC (ICMP) at the computer logon
and user logon.
Why ? And what are the consequences if ICMP is blocked ?
I don't manage a KB which deals with that.

Thanks !

--
P.A.



.



Relevant Pages

  • Re: Basic IPTable filter
    ... > Incoming packets ... > Accept If protocol is ICMP and rate is less than 5/sec ... firewall host itself isn't running ANYTHING other than the firewall... ...
    (comp.os.linux.security)
  • Re: ICMP Ping and Group Policy Update
    ... sounds like folks pretty much confirmed that blocking ICMP blocks ... Group Policy updates for at least some users. ... stopping 40 byte packets. ...
    (NT-Bugtraq)
  • Re: XP-SP2 "Feature"
    ... What about Group Policy? ... Does anyone know if XP/2K Pro require ICMP to ... order for Group Policy to work across firewalls. ... >>Systems Analyst ...
    (Focus-Microsoft)
  • Re: ICMP Ping and Group Policy Update
    ... we blocked ICMP Pings to & from our VPN. ... > it appears that this also has disabled group policy updates for remote ... when a client machine attempts to connect to ... ICMP pings to the DC in order to test connectivity and link speed. ...
    (NT-Bugtraq)
  • RE: XP-SP2 "Feature"
    ... I recently took a class on applying MS security features and I did not ... icmp did not work but GPO still worked. ... What about Group Policy? ... be open across firewalls? ...
    (Focus-Microsoft)