Reply
Highlighted
L3 Networker

About APP-ID icmp and ping.

Hi guys.

I have question about APP-ID that ICMP and PING. I found that some document said "ICMP is all of icmp procol and PING is only ICMP type 0 and 7 is echo request and reply".

When we have white list security policy, For open a PING application, Shoud we open ICMP and PING also? I think they has got app-dependency so ICMP must be opend and also ping should be opend. right?

Thanks.

Regards.

Roh.


Accepted Solutions
Highlighted
L6 Presenter

Re: About APP-ID icmp and ping.

Typically, users want to discuss denial of ping vs icmp. Here's a general feedback.

ICMP is not available in the "Service" column of the security policies.  Instead the option is available in the "Application" column.  However, you should exercise caution when denying the protocol ICMP, as this will effect all ICMP packets and any application reliant on the protocol.  The alternative option is to simply deny PING as an application, which uses ICMP Type 8 (Echo Request) and 0 (Echo Reply).

View solution in original post


All Replies
Highlighted
L6 Presenter

Re: About APP-ID icmp and ping.

Typically, users want to discuss denial of ping vs icmp. Here's a general feedback.

ICMP is not available in the "Service" column of the security policies.  Instead the option is available in the "Application" column.  However, you should exercise caution when denying the protocol ICMP, as this will effect all ICMP packets and any application reliant on the protocol.  The alternative option is to simply deny PING as an application, which uses ICMP Type 8 (Echo Request) and 0 (Echo Reply).

View solution in original post

L3 Networker

Re: About APP-ID icmp and ping.

Hello rkalugdan

Thank you for kind answer!

Regards.

Roh

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!