Hi, what I would do to see if everything is alright:
1. traceroute from your fw to the external ping-website 2. if you tag "accept ICMP", the default value is "before last". To make sure that nothing in your rulebase leads to unexpected behaviour concerning ICMP I would change this setting to "first" (for a short time only) and do the tests. --Joerg http://www.firewalls-illustriert.de -----Urspr�ngliche Nachricht----- Von: v.r [mailto:[EMAIL PROTECTED] Gesendet: Donnerstag, 3. April 2003 11:29 An: [EMAIL PROTECTED] Betreff: [FW-1] Interface Ping Hello, Iam using NG Fp3.When iam pinging the external interface from a internet ping website, my external interface is accepting the ping but not giving the response. there are no antispoofing configuration specified. In the global, ICMP is accepted. the default gateway for the firewall at the external side is pingable from the internet. do i need to add the echo reply also to get the ping response at the external interface?? thanks, v.r ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
