<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27699#M20194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May I suggest you take a look at the Zone Protection feature.&amp;nbsp; The feature can be enable to detect &amp;amp; block ICMP fragmentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Jan 2012 17:54:48 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-01-09T17:54:48Z</dc:date>
    <item>
      <title>ICMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27698#M20193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When creating an application ID for the ICMP can you specifiy the codes, right now it just seems to cover only the types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reason being is that due to security restrictions only certain types of ICMP traffic is allowed to cross one type of ICMP that needs to be allowed it type 3 code 4 which is for the packet fragmentation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 11:17:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27698#M20193</guid>
      <dc:creator>snormoyle</dc:creator>
      <dc:date>2012-01-09T11:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27699#M20194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May I suggest you take a look at the Zone Protection feature.&amp;nbsp; The feature can be enable to detect &amp;amp; block ICMP fragmentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 17:54:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27699#M20194</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-01-09T17:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27700#M20195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response, but I guess did not make myself clear enough on what I am trying to accomplish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With our current firewall we have rules to allow only certain type of ICMP traffic, while the rest will get denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;internal network --&amp;gt; outside&amp;nbsp;&amp;nbsp; ***allow the following ICMP types&lt;/P&gt;&lt;P&gt;icmp echo&lt;/P&gt;&lt;P&gt;icmp echo-reply&lt;/P&gt;&lt;P&gt;icmp time-exceeded&lt;/P&gt;&lt;P&gt;icmp source-quench&lt;/P&gt;&lt;P&gt;icmp destination unreachable/fragmentation required, DF flag set (type 3 code 4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I can create an application ID for the different ICMP types, but when you are creating an application type of ICMP it only allows you specify the type, but not the code.&amp;nbsp; If I am creating an application ID for ICMP for type 3 it would allow all type 3 traffic, but what I want is to only allow type 3 code 4 ICMP packets. All the other ICMP type 3 packets are to be dropped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jan 2012 12:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27700#M20195</guid>
      <dc:creator>snormoyle</dc:creator>
      <dc:date>2012-01-10T12:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27701#M20196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The answer is no. Currently we have an application called PING and an application called ICMP. This is the only granularity at this time. You may be able to create a Custom App that uses the type field to get more specific.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2012 19:33:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/icmp/m-p/27701#M20196</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2012-01-17T19:33:33Z</dc:date>
    </item>
  </channel>
</rss>

