<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block ICMP to FTD Device Interface IP in FDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/m-p/4152340#M1073965</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I have a small Firepower 1010 appliance without FMC. One requirement here is to block pings to the IPs of the device / its interfaces.&lt;BR /&gt;My research revealed that this setting can be set in the FMC via the platform settings using ICMP rules.&lt;BR /&gt;But since I only manage the appliance via the FDM, how can I block incoming pings directed to the firewall itself? Within the WebUI I did not find a corresponding setting, the same applies to the CLI.&lt;/P&gt;&lt;P&gt;Cheers and thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2020 21:59:37 GMT</pubDate>
    <dc:creator>MxShay</dc:creator>
    <dc:date>2020-09-16T21:59:37Z</dc:date>
    <item>
      <title>Block ICMP to FTD Device Interface IP in FDM</title>
      <link>https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/m-p/4152340#M1073965</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I have a small Firepower 1010 appliance without FMC. One requirement here is to block pings to the IPs of the device / its interfaces.&lt;BR /&gt;My research revealed that this setting can be set in the FMC via the platform settings using ICMP rules.&lt;BR /&gt;But since I only manage the appliance via the FDM, how can I block incoming pings directed to the firewall itself? Within the WebUI I did not find a corresponding setting, the same applies to the CLI.&lt;/P&gt;&lt;P&gt;Cheers and thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 21:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/m-p/4152340#M1073965</guid>
      <dc:creator>MxShay</dc:creator>
      <dc:date>2020-09-16T21:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Block ICMP to FTD Device Interface IP in FDM</title>
      <link>https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/m-p/4152415#M1073966</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the bottom of the main dashboard on FDM, go to Advanced Configuration.&lt;/P&gt;
&lt;P&gt;Create a Flexconfig Object like:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;icmp deny any inside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and the following command on negate field:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;no icmp deny any inside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It could also be:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;icmp permit x.x.x.x 255.255.255.0&lt;/STRONG&gt; inside&lt;/P&gt;
&lt;P&gt;and the following on negate field:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;no icmp permit x.x.x.x 255.255.255.0 inside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then attach this object on Flexconfig policy and deploy the config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The platform setting ICMP configuration on FMC pushes this configuration directly to lina and let you avoid creating a manual flexconfig.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 02:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/m-p/4152415#M1073966</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-09-17T02:58:27Z</dc:date>
    </item>
  </channel>
</rss>

