With usual TCP and UDP, you block by default, allow outgoing, allow replies and your internet works (consumer defaults). If you want, you allow specific incoming ports and it's good enough for most use cases. It's almost trivial to configure a reasonable basic firewall, and you can learn all you need in 5-10 minutes.
With ICMP, there is this long list of types and subtypes, some of which sound dangerous while others necessary. Which ones should you block and which ones should you allow?
Do you expect everyone to create an accurate threat model? People have lives. So, some people end up blocking ICMP and internet "works" except .. of course it doesn't.
This is the internet eqivalent of dumping your sewage in the lake because it's too difficult to deal with properly.
People that do this externalise the costs of their choices onto everyone else, and it takes a bunch of specialists to identify what's happening and educate the problematic network operator, and/or clean up the mess.
Doing a search on should I block ICMP, or what ICMP to block, answers are:
[1] No!!; some security issues; a lot of ICMP should be blocked; suggests further research
[2] you should selectively filter; example iptables rule to allow echo; assess evaluate and make your own rules
[3] listing of types and RFC recommendations for transit and local traffic
So I guess I should take "Should Be Dropped" and "Policy Should be Defined" from [3] and plug them into [2]. Why is it so hard?
Why isn't the answer: "No, defaults are safe, no need to block anything", or "Select one of: Endpoint / Site firewall / Internet router; customize if needed"?
IMO, this is a mess. This is the ultimate cause of all the sewage, time spent both debugging, and even more on learning what and how to block, configuring it all. Issues like this even hinder IPv6 adoption, because who is going to deal with all the complexity.
[1] http://shouldiblockicmp.com/
[2] https://blog.securityevaluators.com/icmp-the-good-the-bad-an...
[3] https://serverfault.com/questions/981558/which-ipv4-6-icmp-t...
> Doing a search on ... answers are:
Sorry, "Google search results" are not "up the chain". That's your first mistake.
There's a tonne of misinformation in Google search results. It's real hard to identify what's good and what's not if you're not a specialist in the field, so it's easy to fall victim to this and just believe well meaning well written blog posts.
Don't do this. When you don't know something, speak to someone who does know about the subject matter at hand. Not anonymous people on the internet, but someone in reality that you can have a conversation with. If it's a topic that's vaguely within the remit of someone you work with, that's a good place to start.