<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabled Mgmt interface of firewall responds to ping in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/85995#M17253</link>
    <description>&lt;P&gt;How was the interface disabled and what was the source of the ping?&lt;/P&gt;
&lt;P&gt;When you say the Mgmt interface note the 'role' can be assigned to another port on the appliance...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 May 2020 12:46:30 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2020-05-21T12:46:30Z</dc:date>
    <item>
      <title>Disabled Mgmt interface of firewall responds to ping</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/85975#M17247</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are running R80.30 and we noticed that when we ping the mgmt. interface of the firewall, even though it is not enabled, it responds to ping.&lt;/P&gt;&lt;P&gt;We performed fw monitor -e "host(mgmt_ip),accept;" and run a continuous ping. The request passes the IN interface (iI) and then exits again through the same interface (oO) as expected.&lt;/P&gt;&lt;P&gt;We would have thought that because the mgmt. interface is not enabled, we shouldn't get a response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone explain this behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance,&lt;/P&gt;&lt;P&gt;Katerina&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 08:39:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/85975#M17247</guid>
      <dc:creator>kadar2</dc:creator>
      <dc:date>2020-05-21T08:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Mgmt interface of firewall responds to ping</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/85986#M17248</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If you run a ping directly from the firewall to the mgmt intf when it's in off state, it's normal to respond to ping because locally it doesn't care about the state of the interface, unlike other vendors. From an external device the ping won't/shouldn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 09:44:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/85986#M17248</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-05-21T09:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Mgmt interface of firewall responds to ping</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/85995#M17253</link>
      <description>&lt;P&gt;How was the interface disabled and what was the source of the ping?&lt;/P&gt;
&lt;P&gt;When you say the Mgmt interface note the 'role' can be assigned to another port on the appliance...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 12:46:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/85995#M17253</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-05-21T12:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Mgmt interface of firewall responds to ping</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/86041#M17259</link>
      <description>&lt;P&gt;By saying "disabled", we see through GAIA that the port is not enabled and it has no physical connection to the rest of the infrastructure.&lt;/P&gt;&lt;P&gt;Its main purpose is to function as an out-of-band mgmt, if the connectivity to the actual management interface is not permitted, so you are right in stating that it is not the actual management interface.&lt;/P&gt;&lt;P&gt;The ping was performed from outside the firewall (user PC).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 07:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/86041#M17259</guid>
      <dc:creator>kadar2</dc:creator>
      <dc:date>2020-05-22T07:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Mgmt interface of firewall responds to ping</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/86086#M17276</link>
      <description>Disabling the interface does not deassociate the IP address assigned to that interface from the appliance.&lt;BR /&gt;As such, if a ping for a disabled interface is received on a different interface, the appliance will respond to it.&lt;BR /&gt;This is expected behavior.</description>
      <pubDate>Fri, 22 May 2020 19:20:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Disabled-Mgmt-interface-of-firewall-responds-to-ping/m-p/86086#M17276</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-22T19:20:26Z</dc:date>
    </item>
  </channel>
</rss>

