Thanks to all that did reply.
After considering all input given I decided to stand firm and deny the request to
allow ping packets to reach our DMZ host. There's soon going to be a call center for
this app and if a customer thinks the web server isn't reachable, the call center can
quickly verify this by checking the system from the inside. One thing less to worry
about for me as a security administrator <s>
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================