log for basic rule to ping fw interface shows pass but there is not icmp reply
-
Hello everybody,
my setup is for virtual lab so i have lan and dmz interface only.
i would like to have my dmz servers to be able ping fw dmz interface. Log for the rule allowing icmp from the dmz subnet towards fw interface ip shows pass, but in tcpdump there is no icmp reply and of course hosts console says host unreachable.
I do not see any other traffic blocked. Is there any specific feature to allow ping on FW interface?
rule which triggers:
pass in log quick on vmx1 inet proto icmp from 10.1.10.0/24 to 10.1.10.1 keep state label "USER_RULE: ping to fw dmz int"thank you
horc -
Interesting, no advice? no suggestions? :)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.