<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permit ICMP request only in several networks in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34520#M7260</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They are called Global Properties for a reason. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Exceptions one way or the other need explicit rules.&lt;/P&gt;&lt;P&gt;Is there a specific reason you want to use Global Properties and not an explicit rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 23 Feb 2019 04:59:03 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-02-23T04:59:03Z</dc:date>
    <item>
      <title>Permit ICMP request only in several networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34515#M7255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For security reasons, I have disabled the "Accept ICMP request" box in the global properties of a cluster checkpoint 5400 version R77.30.&lt;BR /&gt;The case is that a client / server application needs this traffic through a VPN.&lt;BR /&gt;Can this traffic be enabled safely only for certain networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 08:50:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34515#M7255</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-02-20T08:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: Permit ICMP request only in several networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34516#M7256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most of the time all they need is Echo-Request, the reply is part of the standard statefull inspection so does not need to be added. You can just add that service to a rule allowing the traffic back and forth.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 13:06:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34516#M7256</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-20T13:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: Permit ICMP request only in several networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34517#M7257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I want to know is if we can enable this feaure in policy -&amp;gt; global properties -&amp;gt; accept ICMP without compromising security by restricting the traffic allowed only to the source IPs of the VPN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 15:25:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34517#M7257</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-02-20T15:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Permit ICMP request only in several networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34518#M7258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically, we want to know if we can to enable the ACCEPT ICMP in global properties, keeping or restric some IPs into a VPN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 15:32:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34518#M7258</guid>
      <dc:creator>Jesus_Cano</dc:creator>
      <dc:date>2019-02-20T15:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Permit ICMP request only in several networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34519#M7259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you enable it in the global properties, and do it as Before last, you can still apply a drop rule for specific networks, but to be honest I don't like the things that apply to all traffic, to be enabled on a global level. I rather be specific on allowing Ping. We see a lot of times that ICMP as a protocol has been allowed, which is not really what you want. There are to many ICMP items that can be used maliciously.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 16:14:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34519#M7259</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-20T16:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Permit ICMP request only in several networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34520#M7260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They are called Global Properties for a reason. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Exceptions one way or the other need explicit rules.&lt;/P&gt;&lt;P&gt;Is there a specific reason you want to use Global Properties and not an explicit rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2019 04:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Permit-ICMP-request-only-in-several-networks/m-p/34520#M7260</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-23T04:59:03Z</dc:date>
    </item>
  </channel>
</rss>

