• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Blocking ICMP (ping) from my DMZ.

Scheduled Pinned Locked Moved Firewalling
3 Posts 3 Posters 466 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    nafeasonto
    last edited by Dec 18, 2017, 7:36 AM

    So I don't understand why this isn't wrking, but I go into the RULES for the DMZ.  Like DMZ from the srouce of any  to LAN NET, no ICMP.
    Then IN the LAN, I block ICMP from source of DMZ net to LAN NET.

    But ping is still getting through, why?

    here is screenie.

    https://imgur.com/a/EXUA4

    1 Reply Last reply Reply Quote 0
    • G
      GruensFroeschli
      last edited by Dec 18, 2017, 8:31 AM

      Did you keep the ping running while changing rules?
      Have you tried to stop the ping and then start it again?

      States created before you change the rules will not automatically be killed.
      You can manually trigger a kill of all states under:
      Diagnostic –> States -->"Reset States"

      We do what we must, because we can.

      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Dec 18, 2017, 1:31 PM

        Your source net dmz net rule on lan is pointless.

        Your rules below that any any rule on dmz are pointless.

        As GruensFroeschli correctly stated, if you had a state that allowed ping when you created that block rule.. You would have to kill any active states to lan to allow the rule to be used.  Since active states are looked at before rules are evaluated.  You do not need to kill/reset all states.. You can look under your state table for the specific state(s) you want to kill and just kill those.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        2 out of 3
        • First post
          2/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received