<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to allow only ICMP Echo Request; Firewall passes all the traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19977#M14555</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We ran into this same problem.&amp;nbsp; When you put 'PING' in the Application and leave the Source to 'any' it allows any TCP/UDP traffic.&amp;nbsp; We are going to change the policy and see if 'default-application' fixes it.&amp;nbsp; However, I agree that this is an issue.&amp;nbsp; It is mis-leading to have a policy that states a firewall only allows PING traffic as the application on 'any' service, and yet allows ALL traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Oct 2011 20:07:05 GMT</pubDate>
    <dc:creator>UtilitySecurity</dc:creator>
    <dc:date>2011-10-10T20:07:05Z</dc:date>
    <item>
      <title>Unable to allow only ICMP Echo Request; Firewall passes all the traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19975#M14553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 networks in 2 different security zones. I have been trying to set up the firewall (PA-500) to &lt;SPAN style="color: #333333;"&gt;allow &lt;SPAN style="text-decoration: underline;"&gt;only&lt;/SPAN&gt; icmp echo request (ping), which is an icmp message number 8 and 0 between the two networks. When using predefined application called "ping" it allows other traffic and not just the icmp ping. I have also tried to create a custom application rule that would define icmp message number 8, but it does exact same thing as the predefined "ping". The rule would look like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Zone&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destinatio Zone&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Addr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source User&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dest Addr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; App&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service Act&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Profile&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;ICMP Ping between&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Zone1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Zone2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; none&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;zones&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;When I run tcpdump or such utility on Zone2 host I see also TCP and UDP traffic. The firewall Monitor tells me that this is the rule that allows the other traffic. This could be a potential security issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;Any suggestions would be greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Mar 2011 20:17:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19975#M14553</guid>
      <dc:creator>dkraus</dc:creator>
      <dc:date>2011-03-22T20:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to allow only ICMP Echo Request; Firewall passes all the traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19976#M14554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe instead of specifying your Service as "any" try using "application-default" ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Mar 2011 23:29:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19976#M14554</guid>
      <dc:creator>KGC</dc:creator>
      <dc:date>2011-03-22T23:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to allow only ICMP Echo Request; Firewall passes all the traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19977#M14555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We ran into this same problem.&amp;nbsp; When you put 'PING' in the Application and leave the Source to 'any' it allows any TCP/UDP traffic.&amp;nbsp; We are going to change the policy and see if 'default-application' fixes it.&amp;nbsp; However, I agree that this is an issue.&amp;nbsp; It is mis-leading to have a policy that states a firewall only allows PING traffic as the application on 'any' service, and yet allows ALL traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 20:07:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19977#M14555</guid>
      <dc:creator>UtilitySecurity</dc:creator>
      <dc:date>2011-10-10T20:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to allow only ICMP Echo Request; Firewall passes all the traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19978#M14556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@gmoorman:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you can demonstrate that a security policy with action = allow, service = any and application = ping is allowing TCP or UDP traffic then I advise you to contact support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 20:35:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19978#M14556</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-10-10T20:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to allow only ICMP Echo Request; Firewall passes all the traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19979#M14557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got exactly the same kind of issue :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/thread/3715?tstart=0"&gt;https://live.paloaltonetworks.com/thread/3715?tstart=0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is weird...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 12:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-allow-only-icmp-echo-request-firewall-passes-all-the/m-p/19979#M14557</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2011-11-11T12:58:56Z</dc:date>
    </item>
  </channel>
</rss>

