Moderators: wendy
Go
New
Find
Notify
Tools
Reply
  
-star Rating Rate It!  Login/Join 
Junior Member
Posted
I have a S/A 225 with 8.029x. I need to allow ICMP outbound from the LAN.
I have created a rule to allow it, but the log shows it is being blocked as "Stateless ICMP" by rule -1.

Is there a way to allow this without lowering the security level setting below medium?

Thanks,
Jeff
 
Posts: 13 | Registered: December 06, 2007Reply With QuoteEdit or Delete MessageReport This Post
Technical Support Team Manager
SofaWare Employee - Senior Engineer
Posted Hide Post
Stateless ICMP means basically that a ping packet has been sent/received when the communications (SYN) process has been closed.

Please check to see if this only occurs on one internal PC it might be a troublesome program or other malware or bad network card.


Sagy Kratu
Technical Support Team Manager
 
Posts: 57 | Registered: January 04, 2007Reply With QuoteEdit or Delete MessageReport This Post
Junior Member
Posted Hide Post
Hi Sagy,

Thanks for the reply.

I'm trying to get a license from a license server. I am using a VPN to connect to the safe@, then allow and forward to the license server. The traffic is all UDP. The license server license is tied to the mac address of the nic, so I can't test a different machine or nic in this case.

I was under the impression that user defined rules override the default security policy, so my 1st rule is allow ICMP from internal networks to Any.

I've looked through the SmartDefense rules, but didn't see anything applied that I thought would cause a problem.

Do you have any other suggestions?

Thanks,
Jeff
 
Posts: 13 | Registered: December 06, 2007Reply With QuoteEdit or Delete MessageReport This Post
 Previous Topic | Next Topic powered by eve community  
 


© Copyright 2006 SofaWare Technologies Ltd.
How To Buy