The principle of Huawei Firewall processing ICMP messages
Experimental topology
Add policies to the firewall so that the trust area can access the untrust area, use the PC ping external server, and grab the packet at the same time
View session information on the firewall
Grabbing the interface packet of g0ram 0ax 1 on the firewall.
Open the icmp packet, you can see the identifier mark, use the calculator to convert to decimal system to get 53607
Looking at the firewall session table, you can see that the source port number of the icmp session is 53607
You can view the second packet authentication
The source port number of the same session table is the same as the identifier of the icmp data message, and the destination port number is 2048.