<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limit ICMP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250265#M48890</link>
    <description>&lt;P&gt;Oh, that's different.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt; &amp;nbsp;I thought you were trying to report some other issue.&lt;/P&gt;</description>
    <pubDate>Fri, 30 May 2025 20:37:28 GMT</pubDate>
    <dc:creator>Duane_Toler</dc:creator>
    <dc:date>2025-05-30T20:37:28Z</dc:date>
    <item>
      <title>Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250254#M48886</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi guys&lt;/P&gt;&lt;P&gt;Some firewall settings may cause a certain packet size to not pass through the ping.&lt;BR /&gt;for example:&lt;BR /&gt;Ping 8.8.8.8 -l 1000 Passes&lt;BR /&gt;Ping 8.8.8.8 -l 4000 Does not pass&lt;/P&gt;&lt;P&gt;I've attached a test image.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ping.PNG" style="width: 497px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30647i4A56D3455AF597B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Ping.PNG" alt="Ping.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 17:55:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250254#M48886</guid>
      <dc:creator>DanielJavier</dc:creator>
      <dc:date>2025-05-30T17:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250255#M48887</link>
      <description>&lt;P&gt;#WorksForMe&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 18:07:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250255#M48887</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-05-30T18:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250260#M48889</link>
      <description>&lt;P&gt;check your IPS core protections for "max ping size" - I am seeing a default of 2500 bytes if it is enabled.&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 20:35:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250260#M48889</guid>
      <dc:creator>Lloyd_Braun</dc:creator>
      <dc:date>2025-05-30T20:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250265#M48890</link>
      <description>&lt;P&gt;Oh, that's different.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt; &amp;nbsp;I thought you were trying to report some other issue.&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 20:37:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250265#M48890</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-05-30T20:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250270#M48891</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4fakj6" style="width: 612px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30654i764306A1DC27E721/image-size/large?v=v2&amp;amp;px=999" role="button" title="4fakj6" alt="4fakj6" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 20:47:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250270#M48891</guid>
      <dc:creator>Lloyd_Braun</dc:creator>
      <dc:date>2025-05-30T20:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250290#M48903</link>
      <description>&lt;P&gt;There are actually two protections that can limit the size of pings:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Core Activation: Large Ping Size (default limit 2500 bytes)&lt;/LI&gt;
&lt;LI&gt;ThreatCloud Protection: Max Ping Echo Reply Size (default limit 512 bytes)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To make things even more confusing the first is one of the fixed 39 Core Activations, while the other one is part of the much more numerous (and always growing) ThreatCloud Protections.&amp;nbsp; The main thing to watch out for is they are controlled by their own profiles and exceptions, so adding a standard Threat Prevention exception will only apply to the second protection and not the first.&amp;nbsp; Core Activations have their own separate set of exceptions (and better yet so do the 146 Inspection Settings).&lt;/P&gt;
&lt;P&gt;The differences between working with Core Activations vs. IPS ThreatCloud protections is a major source of confusion, and nicely covered by the &lt;A href="https://training-certifications.checkpoint.com/#/courses/Threat%20Prevention%20Specialist%20R81.20%20(CTPS)" target="_blank" rel="noopener"&gt;Check Point Threat Prevention Specialist (CTPS)&lt;/A&gt; course available from ATCs worldwide.&lt;/P&gt;</description>
      <pubDate>Sat, 31 May 2025 19:21:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/250290#M48903</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-05-31T19:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273569#M104138</link>
      <description>&lt;P&gt;Regarding the two IPS protections:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Core Activation: Large Ping Size (default limit 2500 bytes)&lt;/LI&gt;&lt;LI&gt;ThreatCloud Protection: Max Ping Echo Reply Size (default limit 512 bytes)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;A client's recent pentest report recommended setting the maximum ping size to 64 bytes. I am concerned that this may break valid traffic. Should i be concerned?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 05:44:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273569#M104138</guid>
      <dc:creator>jimm</dc:creator>
      <dc:date>2026-03-17T05:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273584#M104146</link>
      <description>&lt;P&gt;A typical ping packet has 32 payload bytes, plus 8 bytes of ICMP header, for a total of 40 bytes, then another 20 bytes for the IP header, and another 14 bytes or so for the Ethernet header.&amp;nbsp; I'm assuming the Protection limit is for the ICMP portion (40 bytes by default).&lt;/P&gt;
&lt;P&gt;I actually like sending large pings as they tend to aggravate packet loss issues and make them a little easier to see:&lt;/P&gt;
&lt;P&gt;Gaia/Linux: ping -s 1400 129.82.102.32&lt;BR /&gt;Windows: ping -l 1400 129.82.102.32&lt;/P&gt;
&lt;P&gt;I can't think of any scenario where ping packets larger than standard would be used other than the above.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 12:42:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273584#M104146</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-03-17T12:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273585#M104147</link>
      <description>&lt;P&gt;You will affect some hosts that try to do Path MTU discovery with ICMP (by sending giant ping packets), but they will still work unless they also switch to other methods such as TCP. &amp;nbsp;There are other (more proper) ways to do PMTU discovery, and giant ICMP packets aren't the best, but some firmware programmers never seemed to understand that.&lt;/P&gt;
&lt;P&gt;You'll know who they are when you see IPS Prevent logs for ICMP. &amp;nbsp;At that point, you can decide if you want to create exceptions for them or not. &amp;nbsp;You won't destroy their ability to function, but you will generate more logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 13:13:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273585#M104147</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-03-17T13:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273666#M104188</link>
      <description>&lt;P&gt;Thank you for the replies. Looking at the settings, i cannot see where to change the max ping size from its default value. Where can i adjust that?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 00:54:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273666#M104188</guid>
      <dc:creator>jimm</dc:creator>
      <dc:date>2026-03-18T00:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Limit ICMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273670#M104189</link>
      <description>&lt;P&gt;It's in the list of IPS Protections. &amp;nbsp;Here's the configuration you want:&lt;/P&gt;
&lt;P&gt; Select and edit the protection item:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-03-17 at 9.44.40 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33790iD785A3DE1B4DF2B0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2026-03-17 at 9.44.40 PM.png" alt="Screenshot 2026-03-17 at 9.44.40 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Set it&amp;nbsp;to Accept for your profile, if it's not already:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-03-17 at 9.44.59 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33791iF9C010272579D9BB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2026-03-17 at 9.44.59 PM.png" alt="Screenshot 2026-03-17 at 9.44.59 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Edit the Advanced section and enter the max number of bytes you want:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-03-17 at 9.45.07 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33792i6F0F47FB27841462/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2026-03-17 at 9.45.07 PM.png" alt="Screenshot 2026-03-17 at 9.45.07 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 01:46:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limit-ICMP/m-p/273670#M104189</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-03-18T01:46:43Z</dc:date>
    </item>
  </channel>
</rss>

