- CheckMates
- :
- Products
- :
- General Topics
- :
- There is no ping to the DMZ
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is no ping to the DMZ
Hello Check Mates.
There are 2 local networks. For example, first local with PCs 172.16.0.0/24 and the second one is 172.18.0.0/24.
There are a lot of rules on the Check Point Security Gateway, but all of them are chaged to Accept.
In the global properties Accept ICMP is disabled. Although I changed it to first, then before last, so none of them didn't help.
Also there are NO LOGS about ICMP except nbmudp (Idk how to write it correctly) to that host, which is allowed. In the Track field logging was enabled at the all rules in the policy.
I have only one explanation of that: this is a lag of SmartConsole or Gateway.
Is that possible? Have you ever faced with that problem? Does lagging of Check Point able to do this?
- Tags:
- icmp
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The best way to troubleshoot this is what I like to call "follow the bouncing packet."
Pick a host in one subnet and ping one in the target one.
Use tcpdump or fw monitor to see if the ICMP Echo Request packet from the source arrives on the appropriate interface.
I can provide more guidance if you answer the following questions:
- Does the ICMP Echo Request from the host arrive to the gateway on the expected interface? (If not, it's probably a routing issue elsewhere unrelated to the firewall)
- Does the ICMP Echo Request from the host leave the gateway towards the destination host on the expected interface? (If not, that will require some troubleshooting)
- If the ICMP Echo Request is sent towards the host, does an ICMP Echo Reply arrive from the destination host on the same interface? (If not, it's probably a routing/ARP issue)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, Dameon! It's certainly useful information for my future issues.
The problem was solved. You're right, it may be related to the routing through approriate interfaces. So the client changed an interface on DMZ server and the ping appeared.
![](/skins/images/74119E49EB1AA30407316FFB9151D237/responsive_peak/images/icon_anonymous_message.png)