>
> I'm not able to ping from certain site despite the following settings
below.
> Any ideas anyone ?
>
> Thanks.
>
>
> Policy properties, checked accept icmp last
>
> Rulebase:
> Source :site xxx
> Destination: internal machine-A
> Service : icmp echoreply,icmp timeexceeded, icmp dest-unreach
> Action : allow
>

I think you have to add a rule to allow the ICMP echoreply enter in your
network.

Source                     Destination                       Service
Action
Any                       internal-machine
echoreply,timeexceed,dest-unreach                            Allow
interna-machine         Any
echorequest,traceroute                                                Allow


Hope it helps...




================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to