Enabling sending ICMP error messages for NAT failures

Disabling sending ICMP error messages for NAT failures reduces useless packets, saves bandwidth, and avoids exposing the firewall IP address to the public network.

This feature is required for traceroute.

To enable sending ICMP error messages for NAT failures:

Step

Command

Remarks

1. Enter system view.

system-view

N/A

2. Enable sending ICMP error messages for NAT failures.

nat icmp-error reply

By default, no ICMP error messages are sent for NAT failures.