- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All
Can we ping any PC directly connected to SG?
Connectivity:
SG----->Router(192.168.116.200)----Local Network---->PC(192.168.116.1)
Not able to ping PC from SG, But getting ping from SG to Router Local network Gateway IP 192.168.116.200. Why?
As able to reach local network gateway, then why not getting Ping from local PC.
Please suggest how can achieve this.
What have to do for this
Hi Ravinder,
Assuming your topology resembles the one above, I would say that all you need to do is to add a route on your gateway.
In Clish:
set static-route 192.168.116.0/24 nexthop gateway address [ip-address-of-router-residing on the same subnet as your firewall] priority 1 on
save config
ping 192.168.116.1
I hope this helps.
I would also recommend checking logs to make sure ICMP isn't being dropped for some reason. Depending on your Global Properties and/or Access Policy, you may need a rule explicitly allowing this. You may have some drop rule dropping it.
You may also want to look for Anti-Spoofing events in your logs if your Topology isn't defined properly and the GW thinks the remote network on the other side of the router is spoofing. (Doubtful if other traffic isn't getting blocked, but might be worth a quick check)
Whitch network is between SG and router?
Ping from SG to router in this network
.200 ,1
SG <------------------> Router <---------------------> PC
Network??? 192.168.116.0/24
1) check the rulebase - src:SG dst: 192.168.116.200 service: icmp request/replay
2) if you ping 192.168.116.200 you need a route on the router to the firewall for "Network???". Otherwise you have to ping the interface of the router in the network "Network???".
3) check IP spoofing on the firewall for network 192.168.116.0/24
Hi Nicholas
Static route already added, that's why am able to ping Router Gateway 192.168.116.200. But The system IP not pining.
Regards
Ravinder Gulia
Hi Ravinder,
Could you tell us what is the IP address of the Router's interface that is on the same subnet as the Check Point firewall?
Many thanks.
Hi
That's the topology for this network. Route added at Firewall for the 192.168.116.0 Network and all services allowed in Policy.
Getting ping response on firewall from Router 192.168.116.200 but not from PC IP.
Firewall(172.100.71.9)----------->(172.100.71.10)Router(192.168.116.200)------------->PC(192.168.116.1)
Do you have implied or explicit rules allowing ICMP to the GW? If not, please add.
Hi
will check for the implied rule to allow ICMP. and for explicit rule have made ANY ANY ANY Allow rule.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 36 | |
| 18 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY