Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
DanielJavier
Explorer

Limit ICMP


Hi guys

Some firewall settings may cause a certain packet size to not pass through the ping.
for example:
Ping 8.8.8.8 -l 1000 Passes
Ping 8.8.8.8 -l 4000 Does not pass

I've attached a test image.Ping.PNG

0 Kudos
5 Replies
Duane_Toler
Advisor

#WorksForMe 😕

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos
Lloyd_Braun
Advisor

check your IPS core protections for "max ping size" - I am seeing a default of 2500 bytes if it is enabled.

0 Kudos
Duane_Toler
Advisor

Oh, that's different. 😆  I thought you were trying to report some other issue.

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos
Lloyd_Braun
Advisor

4fakj6

😁

0 Kudos
Timothy_Hall
Legend Legend
Legend

There are actually two protections that can limit the size of pings:

  • Core Activation: Large Ping Size (default limit 2500 bytes)
  • ThreatCloud Protection: Max Ping Echo Reply Size (default limit 512 bytes)

To make things even more confusing the first is one of the fixed 39 Core Activations, while the other one is part of the much more numerous (and always growing) ThreatCloud Protections.  The main thing to watch out for is they are controlled by their own profiles and exceptions, so adding a standard Threat Prevention exception will only apply to the second protection and not the first.  Core Activations have their own separate set of exceptions (and better yet so do the 146 Inspection Settings).

The differences between working with Core Activations vs. IPS ThreatCloud protections is a major source of confusion, and nicely covered by the Check Point Threat Prevention Specialist (CTPS) course available from ATCs worldwide.

Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events