<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP BLOCK ON FTDs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4953611#M1105574</link>
    <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/td-p/4152340" target="_blank"&gt;https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/td-p/4152340&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;use flexconfig to deny ICMP toward FTD interface (not ICMP bypass FTD)&lt;BR /&gt;&lt;BR /&gt;Thanks A Lot &lt;BR /&gt;MHM&lt;/P&gt;</description>
    <pubDate>Sat, 04 Nov 2023 16:18:42 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-11-04T16:18:42Z</dc:date>
    <item>
      <title>ICMP BLOCK ON FTDs</title>
      <link>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4951873#M1105486</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;Managing my FTDs via FMC. Needed help to restrict ICMP on outside interfaces, but allow a few internal endpoints to PING them, for SNMP and other reasons.&lt;/P&gt;&lt;P&gt;Once i do this under platform settings, ICMP is blocked to all, even on the permitted endpoints. Am i doing anything wrong?&lt;/P&gt;&lt;P&gt;Your support will be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 07:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4951873#M1105486</guid>
      <dc:creator>fmugambi</dc:creator>
      <dc:date>2023-11-01T07:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP BLOCK ON FTDs</title>
      <link>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4952297#M1105503</link>
      <description>&lt;P&gt;Hello fmugambi,&lt;/P&gt;
&lt;P&gt;Can you provide more information into what objects and ICMP service are you using for your configuration? If this configuration affects data interfaces you can also create two ACP Rules, one blocking ICMP traffic and other allowing the traffic and you can define which hosts/networks should be blocked specifically there.&lt;/P&gt;
&lt;P&gt;Best regards!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 23:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4952297#M1105503</guid>
      <dc:creator>rveracon</dc:creator>
      <dc:date>2023-11-01T23:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP BLOCK ON FTDs</title>
      <link>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4952390#M1105506</link>
      <description>&lt;P&gt;Under platform settings, then a policy, ICMP Access&amp;nbsp; , ICMP UnReachable ..&lt;/P&gt;&lt;P&gt;Is this the correct way?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 06:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4952390#M1105506</guid>
      <dc:creator>fmugambi</dc:creator>
      <dc:date>2023-11-02T06:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP BLOCK ON FTDs</title>
      <link>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4952776#M1105547</link>
      <description>&lt;P&gt;what are the values here? did you use Deny as action?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HeraldSison_0-1698944834030.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201477i4E0B6960D9739A9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="HeraldSison_0-1698944834030.png" alt="HeraldSison_0-1698944834030.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 17:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4952776#M1105547</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2023-11-02T17:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP BLOCK ON FTDs</title>
      <link>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4953031#M1105552</link>
      <description>&lt;P&gt;Yes I did, and a different entry for permit for endpoints I would wish to reach this ICMP.&lt;/P&gt;&lt;P&gt;But ends up blocking all endpoints.&lt;/P&gt;&lt;P&gt;I as well presume it evaluates the rules top-down, correct?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 05:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4953031#M1105552</guid>
      <dc:creator>fmugambi</dc:creator>
      <dc:date>2023-11-03T05:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP BLOCK ON FTDs</title>
      <link>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4953424#M1105568</link>
      <description>&lt;P&gt;Hello fmugambi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a particular reason why you are using ICMP type 3 (destination unreachable)? What might be happening is that you declare a rule for ICMP 3 denying traffic, then you permit ICMP 3 traffic on other rules, but the actual type you receive on the firewall are type 8 (ICMP requests). So what ends up happening like any kind of ACL is that there is no rule allowing that traffic which ends up dropping everything on the implicit deny rule that exists.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try creating an ICMP rule with type 8 (echo requests) allowing some hosts and test if those hosts can ping again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 23:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4953424#M1105568</guid>
      <dc:creator>rveracon</dc:creator>
      <dc:date>2023-11-03T23:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP BLOCK ON FTDs</title>
      <link>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4953611#M1105574</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/td-p/4152340" target="_blank"&gt;https://community.cisco.com/t5/network-security/block-icmp-to-ftd-device-interface-ip-in-fdm/td-p/4152340&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;use flexconfig to deny ICMP toward FTD interface (not ICMP bypass FTD)&lt;BR /&gt;&lt;BR /&gt;Thanks A Lot &lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 16:18:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-block-on-ftds/m-p/4953611#M1105574</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-04T16:18:42Z</dc:date>
    </item>
  </channel>
</rss>

