- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-03-2011 10:50 PM
Hi guys.
I have question about APP-ID that ICMP and PING. I found that some document said "ICMP is all of icmp procol and PING is only ICMP type 0 and 7 is echo request and reply".
When we have white list security policy, For open a PING application, Shoud we open ICMP and PING also? I think they has got app-dependency so ICMP must be opend and also ping should be opend. right?
Thanks.
Regards.
Roh.
11-08-2011 08:33 PM
Typically, users want to discuss denial of ping vs icmp. Here's a general feedback.
ICMP is not available in the "Service" column of the security policies. Instead the option is available in the "Application" column. However, you should exercise caution when denying the protocol ICMP, as this will effect all ICMP packets and any application reliant on the protocol. The alternative option is to simply deny PING as an application, which uses ICMP Type 8 (Echo Request) and 0 (Echo Reply).
11-08-2011 08:33 PM
Typically, users want to discuss denial of ping vs icmp. Here's a general feedback.
ICMP is not available in the "Service" column of the security policies. Instead the option is available in the "Application" column. However, you should exercise caution when denying the protocol ICMP, as this will effect all ICMP packets and any application reliant on the protocol. The alternative option is to simply deny PING as an application, which uses ICMP Type 8 (Echo Request) and 0 (Echo Reply).
11-10-2011 04:30 PM
Hello rkalugdan
Thank you for kind answer!
Regards.
Roh
11-03-2020 01:36 PM
Can someone explain why a PING fails, even if I allow all ICMP ? Even if you assume PING is application level, I've still allowed it at layer 3. I noticed the same thing with SSH. Thanks.
11-03-2020 10:24 PM
There is one KB article available on PA community given below. This may help you.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIoCAK
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!