Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking ICMP (ping) from my DMZ.

    Firewalling
    3
    3
    447
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nafeasonto
      last edited by

      So I don't understand why this isn't wrking, but I go into the RULES for the DMZ.  Like DMZ from the srouce of any  to LAN NET, no ICMP.
      Then IN the LAN, I block ICMP from source of DMZ net to LAN NET.

      But ping is still getting through, why?

      here is screenie.

      https://imgur.com/a/EXUA4

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Did you keep the ping running while changing rules?
        Have you tried to stop the ping and then start it again?

        States created before you change the rules will not automatically be killed.
        You can manually trigger a kill of all states under:
        Diagnostic –> States -->"Reset States"

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Your source net dmz net rule on lan is pointless.

          Your rules below that any any rule on dmz are pointless.

          As GruensFroeschli correctly stated, if you had a state that allowed ping when you created that block rule.. You would have to kill any active states to lan to allow the rule to be used.  Since active states are looked at before rules are evaluated.  You do not need to kill/reset all states.. You can look under your state table for the specific state(s) you want to kill and just kill those.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.