- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
For security reasons, I have disabled the "Accept ICMP request" box in the global properties of a cluster checkpoint 5400 version R77.30.
The case is that a client / server application needs this traffic through a VPN.
Can this traffic be enabled safely only for certain networks?
thanks
Most of the time all they need is Echo-Request, the reply is part of the standard statefull inspection so does not need to be added. You can just add that service to a rule allowing the traffic back and forth.
What I want to know is if we can enable this feaure in policy -> global properties -> accept ICMP without compromising security by restricting the traffic allowed only to the source IPs of the VPN
Basically, we want to know if we can to enable the ACCEPT ICMP in global properties, keeping or restric some IPs into a VPN.
When you enable it in the global properties, and do it as Before last, you can still apply a drop rule for specific networks, but to be honest I don't like the things that apply to all traffic, to be enabled on a global level. I rather be specific on allowing Ping. We see a lot of times that ICMP as a protocol has been allowed, which is not really what you want. There are to many ICMP items that can be used maliciously.
They are called Global Properties for a reason. ![]()
Exceptions one way or the other need explicit rules.
Is there a specific reason you want to use Global Properties and not an explicit rule?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY