<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ping to 1530 GW from internal net dropped in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99529#M4272</link>
    <description>&lt;P&gt;My guess is it’s a bug of some sort.&lt;BR /&gt;What does fw ctl zdebug drop say?&lt;/P&gt;</description>
    <pubDate>Tue, 20 Oct 2020 02:45:38 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-10-20T02:45:38Z</dc:date>
    <item>
      <title>Ping to 1530 GW from internal net dropped</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99483#M4267</link>
      <description>&lt;P&gt;&lt;SPAN class="test-id__field-value slds-form-element__static slds-grow  is-read-only" data-aura-rendered-by="40:34920;a"&gt;&lt;SPAN class="uiOutputTextArea" data-aura-rendered-by="30:34920;a" data-aura-class="uiOutputTextArea"&gt;Customer has a 1530 SMB appliance in Strict policy mode. He uses a manual rule to enable ping to the GW from internal nets. In firmware R80.20.05 (992001134) this works as expected, but in R80.20.10 (992001491) (and maybe since R80.20.05 (992001208)), ping is dropped by the cleanup rule. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="test-id__field-value slds-form-element__static slds-grow  is-read-only" data-aura-rendered-by="40:34920;a"&gt;&lt;SPAN class="uiOutputTextArea" data-aura-rendered-by="30:34920;a" data-aura-class="uiOutputTextArea"&gt;Question now is with R&amp;amp;D : Is this a Bug or just a new Design ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 10:40:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99483#M4267</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-19T10:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ping to 1530 GW from internal net dropped</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99529#M4272</link>
      <description>&lt;P&gt;My guess is it’s a bug of some sort.&lt;BR /&gt;What does fw ctl zdebug drop say?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 02:45:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99529#M4272</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-20T02:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Ping to 1530 GW from internal net dropped</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99548#M4273</link>
      <description>&lt;P&gt;We did not need to ask fw ctl zdebug drop - according to the logs, ping is dropped by the cleanup rule. The rule not working is:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ping.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8499i2B0C58439CC71948/image-size/large?v=v2&amp;amp;px=999" role="button" title="ping.png" alt="ping.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you substitute the GW object by the GW IP it will match...&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 07:47:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99548#M4273</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-20T07:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ping to 1530 GW from internal net dropped</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99932#M4292</link>
      <description>&lt;P&gt;&lt;FONT face="times new roman,times" size="4"&gt;No bug - R&amp;amp;D answered:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="times new roman,times" size="4"&gt;&lt;BR /&gt;Well, for now this is new design. Please use IP based rules for such scenarios.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 08:41:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ping-to-1530-GW-from-internal-net-dropped/m-p/99932#M4292</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-23T08:41:51Z</dc:date>
    </item>
  </channel>
</rss>

