<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App ICMP vs. Ping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/app-icmp-vs-ping/m-p/42193#M31012</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's take another example- facebook. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Facebook is actually kind of web-browsing, but you still need to allow facebook explicitly in order to get the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To us if we have any sig to cover a specific app, you must allow that specific app in the policy as well in order to allow the traffic. In the real situation for some apps (not icmp) we also need to consider app dependency.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually many traditional firewall do create specific sig for each icmp type traffic and we just create two by default: ping and other icmp traffic (icmp).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Aug 2011 15:40:47 GMT</pubDate>
    <dc:creator>jleung</dc:creator>
    <dc:date>2011-08-11T15:40:47Z</dc:date>
    <item>
      <title>App ICMP vs. Ping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-icmp-vs-ping/m-p/42191#M31010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When icmp is specified as an application in a rule, it appears that icmp requests and replies do not match that rule.&amp;nbsp; The application ping must be added to the rule for a match to occur against echo request and echo reply packets.&amp;nbsp; Isn't ping a subset of the icmp protocol as a whole?&amp;nbsp; I understand how to make this work by adding the application ping, but do not understand why the app icmp does not allow ping.&amp;nbsp; Is the app icmp "all icmp types and codes except ping"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 14:13:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-icmp-vs-ping/m-p/42191#M31010</guid>
      <dc:creator>shadowpeak</dc:creator>
      <dc:date>2011-08-10T14:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: App ICMP vs. Ping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-icmp-vs-ping/m-p/42192#M31011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good question ! I second it!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 14:28:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-icmp-vs-ping/m-p/42192#M31011</guid>
      <dc:creator>lardsa</dc:creator>
      <dc:date>2011-08-10T14:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: App ICMP vs. Ping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/app-icmp-vs-ping/m-p/42193#M31012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's take another example- facebook. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Facebook is actually kind of web-browsing, but you still need to allow facebook explicitly in order to get the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To us if we have any sig to cover a specific app, you must allow that specific app in the policy as well in order to allow the traffic. In the real situation for some apps (not icmp) we also need to consider app dependency.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually many traditional firewall do create specific sig for each icmp type traffic and we just create two by default: ping and other icmp traffic (icmp).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 15:40:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/app-icmp-vs-ping/m-p/42193#M31012</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-11T15:40:47Z</dc:date>
    </item>
  </channel>
</rss>

