Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Couldn't block icmp responses on WAN interface

    Firewalling
    2
    2
    795
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      Guest last edited by

      Hi
      I defined a simple rule on WAN interface to block icmp responses. but i can still  ping 4.2.2.4 from my LAN.

      Action: Block
      Interface: WAN
      Protocol: ICMP
      ICMP type: Any
      Source type: Any
      Destination: Any
      

      If i add a floating rule for "in" direction on WAN, it doesn't block icmp responses too. this rule only works for "out" direction to block icmp requests.
      this problem remains when i change protocol field to any.

      Is this a bug? Can you help me to solve the problem?

      1 Reply Last reply Reply Quote 0
      • johnpoz
        johnpoz LAYER 8 Global Moderator last edited by

        If you don't want users to ping from your lan - then you put the rule on your LAN interface, not your WAN.

        Firewall rules are seen as inbound to the interface, not outbound.  You would not block the response - since there is a state for the outbound traffic you allowed to come back in.

        If you don't want your lan to be able to ping stuff, then put the rule on your LAN, or on your floating tab for your LAN interface.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        2440 2.4.5p1 | 2x 3100 2.4.4p3 | 2x 3100 22.01 | 4860 22.01

        1 Reply Last reply Reply Quote 0
        • First post
          Last post