02-19-2024 05:28 AM
Hi, never found why i can not ping outside marked interfaces on FTD device although via platform settings this is open.
Please refer to the attached screeshot.
Thanks,
Ditter.
Solved! Go to Solution.
02-19-2024 11:58 AM
As mentioned by others here, you cannot ping an FTD interface that is not the ingress interface. If you want to control ICMP packets that are arriving on a specific interface and are destined for the FTD itself, you can use the ICMP menu / ICMP access list to control this traffic.
02-20-2024 12:31 AM
to visualize it:
On each interface, you can use the mentioned platform settings to control which ICMP types are processed. Perhaps you don't want the FTD to be pinged, but you want to allow the FTD itself to ping out of the interface.
02-20-2024 01:16 AM
As the others mentioned, the use of the ICMP menu is to allow or deny specific ICMP types on an interface. However, the traffic flow should always be coming from a source on the same segment as the interface. A source on the outside segment can ping the firewall outside interface, a source on the inside segment can ping the firewall inside interface, and so on.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide