About APP-ID icmp and ping.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

About APP-ID icmp and ping.

L3 Networker

Hi guys.

I have question about APP-ID that ICMP and PING. I found that some document said "ICMP is all of icmp procol and PING is only ICMP type 0 and 7 is echo request and reply".

When we have white list security policy, For open a PING application, Shoud we open ICMP and PING also? I think they has got app-dependency so ICMP must be opend and also ping should be opend. right?

Thanks.

Regards.

Roh.

1 accepted solution

Accepted Solutions

L6 Presenter

Typically, users want to discuss denial of ping vs icmp. Here's a general feedback.

ICMP is not available in the "Service" column of the security policies.  Instead the option is available in the "Application" column.  However, you should exercise caution when denying the protocol ICMP, as this will effect all ICMP packets and any application reliant on the protocol.  The alternative option is to simply deny PING as an application, which uses ICMP Type 8 (Echo Request) and 0 (Echo Reply).

View solution in original post

4 REPLIES 4

L6 Presenter

Typically, users want to discuss denial of ping vs icmp. Here's a general feedback.

ICMP is not available in the "Service" column of the security policies.  Instead the option is available in the "Application" column.  However, you should exercise caution when denying the protocol ICMP, as this will effect all ICMP packets and any application reliant on the protocol.  The alternative option is to simply deny PING as an application, which uses ICMP Type 8 (Echo Request) and 0 (Echo Reply).

Hello rkalugdan

Thank you for kind answer!

Regards.

Roh

Can someone explain why a PING fails, even if I allow all ICMP ?   Even if you assume PING is application level, I've still allowed it at layer 3.   I noticed the same thing with SSH.   Thanks.

@JimmyChernega,

 

There is one KB article available on PA community given below. This may help you.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIoCAK

M

Check out my YouTube channel - https://www.youtube.com/@NetworkTalks
  • 1 accepted solution
  • 7092 Views
  • 4 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!