Hi,

what I would do to see if everything is alright:

1. traceroute from your fw to the external ping-website
2. if you tag "accept ICMP", the default value is "before last". To make
sure that nothing in your rulebase leads to unexpected behaviour concerning
ICMP I would change this setting to "first" (for a short time only) and do
the tests.

--Joerg
http://www.firewalls-illustriert.de


-----Urspr�ngliche Nachricht-----
Von: v.r [mailto:[EMAIL PROTECTED]
Gesendet: Donnerstag, 3. April 2003 11:29
An: [EMAIL PROTECTED]
Betreff: [FW-1] Interface Ping


 Hello,

Iam using NG Fp3.When iam pinging the external
interface from a internet ping website, my external
interface is accepting the ping but not giving the
response.

there are no antispoofing configuration specified. In
the global, ICMP is accepted. the default gateway for
the firewall at the external side is pingable from the
internet.

do i need to add the echo reply also to get the ping
response at the external interface??

thanks,
v.r

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to