Just a few quick notes-
All inbound traffic is denied by default.
When you create a port-forward, there is an option to create the firewall rule. It's checked by default.
To ping the firewall, you would need to add a rule on the WAN to allow ICMP to the WAN address.
If you are using proxy-arp VIPs and port-forwards, the VIPs will not be pingable, even with ICMP allowed.