I'd also make sure that destination-unreachable and  source-quench icmp
types/options are also allowed. Stops MTU from breaking, etc...

 -----Original Message-----
From:   Stefan Dens [mailto:[EMAIL PROTECTED]] 
Sent:   Friday, January 26, 2001 08:12
To:     fw-1-mailinglist
Subject:        [FW1] ICMP



1. Disable Accept ICMP in the Properties
2. make 2 rules:
object -> any    -> echo-request        accept
any    -> object -> echo-reply     accept

any   -> any -> any  drop

-----Oorspronkelijk bericht-----
Van: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]Namens Hermann
Strassner
Verzonden: vrijdag 26 januari 2001 11:25
Aan: Fw-1 Mailinglist
Onderwerp: [FW1] ICMP



How can i setup a rule to allow ping, but to disable all other icmp
options?

Hermann Straßner



========================================================================
====
====
     To unsubscribe from this mailing list, please see the instructions
at
               http://www.checkpoint.com/services/mailing.html
========================================================================
====
====



========================================================================
========
     To unsubscribe from this mailing list, please see the instructions
at
               http://www.checkpoint.com/services/mailing.html
========================================================================
========




================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to