- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-10-2011 07:13 AM
When icmp is specified as an application in a rule, it appears that icmp requests and replies do not match that rule. The application ping must be added to the rule for a match to occur against echo request and echo reply packets. Isn't ping a subset of the icmp protocol as a whole? I understand how to make this work by adding the application ping, but do not understand why the app icmp does not allow ping. Is the app icmp "all icmp types and codes except ping"?
08-11-2011 08:40 AM
Hi,
Let's take another example- facebook.
Facebook is actually kind of web-browsing, but you still need to allow facebook explicitly in order to get the access.
To us if we have any sig to cover a specific app, you must allow that specific app in the policy as well in order to allow the traffic. In the real situation for some apps (not icmp) we also need to consider app dependency.
Actually many traditional firewall do create specific sig for each icmp type traffic and we just create two by default: ping and other icmp traffic (icmp).
Hope this help.
08-10-2011 07:28 AM
Good question ! I second it!
08-11-2011 08:40 AM
Hi,
Let's take another example- facebook.
Facebook is actually kind of web-browsing, but you still need to allow facebook explicitly in order to get the access.
To us if we have any sig to cover a specific app, you must allow that specific app in the policy as well in order to allow the traffic. In the real situation for some apps (not icmp) we also need to consider app dependency.
Actually many traditional firewall do create specific sig for each icmp type traffic and we just create two by default: ping and other icmp traffic (icmp).
Hope this help.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!