<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow ping for proxy arp ip address in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156794#M27062</link>
    <description>&lt;P&gt;Hello RS_Daniel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your detailed explanation. As you have mentioned, I tried to use icmp rule in the nat rule but couldn't install because of verification problem so I thought we can not nat icmp traffic. I tried your method and it is working now.&lt;/P&gt;&lt;P&gt;Thanks a lot to everyone for their help.&lt;/P&gt;&lt;P&gt;Have a great day!&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2022 07:22:31 GMT</pubDate>
    <dc:creator>Ugur_Urel</dc:creator>
    <dc:date>2022-09-08T07:22:31Z</dc:date>
    <item>
      <title>Allow ping for proxy arp ip address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156729#M27038</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Our firewall has several public ip addresses on external interface using proxy arp. Lets assume these public addresses are from 192.168.1.0 network.&lt;/P&gt;&lt;P&gt;Following ip addresses are assigned to interfaces directly;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;192.168.1.1 (node1)&lt;/LI&gt;&lt;LI&gt;192.168.1.2 (node2)&lt;/LI&gt;&lt;LI&gt;192.168.1.3 (cluster ip)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;192.168.1.4 and 192.168.1.5 assigned using proxy arp.&lt;/P&gt;&lt;P&gt;I would like to allow ping the ip address 192.168.1.4 from internet. I have defined a rule for 192.168.1.4 with icmp echo-request, I can see in the logs that traffic accepted but I can not ping from internet. Also if I add 192.168.1.3(cluster ip) to this rule, I can ping 192.168.1.3 from internet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I allow this traffic? By the way "Merge manual proxy arp configuration" option in the global properties is checked.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 10:11:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156729#M27038</guid>
      <dc:creator>Ugur_Urel</dc:creator>
      <dc:date>2022-09-07T10:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ping for proxy arp ip address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156732#M27040</link>
      <description>&lt;P&gt;You've not mentioned the NAT configuration, presumably there is an alive machine behind the proxy-arp address?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 10:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156732#M27040</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-07T10:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ping for proxy arp ip address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156734#M27041</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;No, 192.168.1.4 is a host object on firewall and it is used in several nat rules for port forwarding.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 10:32:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156734#M27041</guid>
      <dc:creator>Ugur_Urel</dc:creator>
      <dc:date>2022-09-07T10:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ping for proxy arp ip address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156750#M27049</link>
      <description>&lt;P&gt;Can you send screenshot of what nat rule looks like?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 13:38:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156750#M27049</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-07T13:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ping for proxy arp ip address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156751#M27050</link>
      <description>&lt;P&gt;Is the ICMP service covered in the scope of your NAT rules?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 23:23:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156751#M27050</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-07T23:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ping for proxy arp ip address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156764#M27056</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;To get ping working you must have an alive machine behind the IP 192.168.1.4 as Chris mentioned. You mentioned you have many manual NATs for this IP, so you must also create a Manual NAT for icmp also, the problem is that icmp services can not be used on a NAT rule, you must use option "Any" to NAT icmp traffic, it should not be a problem, just place this NAT rule with option ANY after all your current manual NAT rules with specific objects. The translated dest could be the internal IP address of the cluster in order to make the firewall answer the icmp requests, or any other internal IP address you want.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 16:27:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156764#M27056</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-09-07T16:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ping for proxy arp ip address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156794#M27062</link>
      <description>&lt;P&gt;Hello RS_Daniel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your detailed explanation. As you have mentioned, I tried to use icmp rule in the nat rule but couldn't install because of verification problem so I thought we can not nat icmp traffic. I tried your method and it is working now.&lt;/P&gt;&lt;P&gt;Thanks a lot to everyone for their help.&lt;/P&gt;&lt;P&gt;Have a great day!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 07:22:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-ping-for-proxy-arp-ip-address/m-p/156794#M27062</guid>
      <dc:creator>Ugur_Urel</dc:creator>
      <dc:date>2022-09-08T07:22:31Z</dc:date>
    </item>
  </channel>
</rss>

