A ping to a host/server with packet size of 997 bytes or more is not working.
Cause
The issue may be occurring due to a configuration that enables packet drop for any packet larger than 1024 bytes in the zone protection profile assigned to the source zone of the originating ping.
Each ping packet as an overhead of 28 bytes. Therefore, the actual byte size of ping packet will be n+28, where n is the byte size that is used to ping. For the example above, the sizes are:
996+28=1024, resulting in a successful ping
997+28=1025, resulting in an unsuccessful ping
Resolution
Go to Network > Network Profiles > Zone Protection.
Select the zone protection profile that is assigned to the zone covering the ping source.
Go to Packet Based Attack Protection > ICMP Drop.
Disable the option for ICMP Large Packet(>1024):
Click 'OK' and commit the changes.
Verification
The following output shows an example where the ICMP Large Packet(>1024) option has been disabled: