Proper Way to Pass ICMP Through Firewall-1?

Proper Way to Pass ICMP Through Firewall-1?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Proper Way to Pass ICMP Through Firewall-1? Will 04-27-2005
Posted by Will on April 27, 2005, 11:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
What is the correct rule to use to allow ICMP packets to pass through a
Checkpoint Firewall-1 firewall? If you have two segments behind a
firewall, and you have a rule to allow all hosts behind one of the segments
to ICMP all hosts on the other segment, how do you set up the rule?

I set a rule to allow the host group for the source segment to ICMP to the
host group for the destination segment. The firewall log shows an Accept
when an ICMP travels from the source to the destination. But the return
ICMP packet never arrives back to the source. I then tried to set a
second rule to allow ICMP from the destination back to the source. This
made no difference. There is no error packet in the log anywhere around
the Accept for ICMP, so whatever is failing is doing so in a way that is
invisible to the firewall log.

I am trying to avoid the "Allow ICMP" setting on the Properties dialog
because it seems far too permissive. I want to find a more strictly
correct way to enable specific ICMPs, using just the ruleset, and I want all
ICMP traffic to be visible in the log.

--
Will





Posted by on April 28, 2005, 5:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hmm,


Some thoughts
* What types of ICMP are you allowing thru ?
* Does the remote servers have a destination gateway other than the
firewall (IP routing loop?) This will break stateful inspection
* Stateful inspection - you should not need a second rule to allow
traffic back to the orginating hosts.
* Does the remote workstaions have the correct gateway?
* Does other connectivity work? FTP/HTTP etc ?



Similar ThreadsPosted
Protecting internal MS Certificate Server with Firewall1 NG FP3 May 11, 2005, 12:29 am
setting up a pass through server February 14, 2005, 11:41 am
VPN pass-through with NetScreen 5 (ScreenOS 5.0.x) July 28, 2006, 1:30 am
Pass-Guaranteed.com Now Hiring!!! January 9, 2007, 5:43 pm
Pass-lock in ZonaAlarm Free March 24, 2006, 3:28 pm
Outgoing emails can not pass through Pix firewall April 7, 2006, 10:13 am
How can I tell Sygate to let networked Laptop pass? June 26, 2006, 6:06 pm
Watchguard Firebox 2 (PPTP and GRE Pass Through) March 20, 2007, 1:28 pm
Belkin, Firewall won't let SMTP or POP3 pass December 23, 2004, 9:52 pm
How to pass GRE Protocol Type 47 through Symantec SGS 320 Firewall Appliance August 29, 2004, 1:03 pm

The site map in XML format XML site map

Contact Us | Privacy Policy