Got it

client can‘t ping local interface on NGFW

Latest reply: Apr 15, 2016 02:19:08 1992 1 0 0 0

Hello all,

Customer configured security to let clients from untrust visit local, but when failed when ping local interfaces on NGFW when ping from clients.

Please help me thanks.

Hello,

Handling Process
1. Check the routings to see if  the packets from clients can reach the IP address which configured on NGFW or not.  And all the routings are ok and we can found one-way session on firewall also.
2. Check the security policy to see if the packets from clients be blocked or not.. And find that the policy allow all the packets from untrust to local .
3. Check the configuration under interfaces to see if there are any rules under ports to block this , and found there are no configuration under interfaces. But as we know for NGFW we have security policy based on Zones and interfaces, and the privilege is higher based on interfacews. That means we need to configure commands"undo service-manage enable" under interface to remove the default block rules under interfaces.
4. When configured "undo service-manage enable" under the local interfaces on firewall and problem has been fixed.
Solution
We need to configure "undo service-manage enable" under interfaces and keep security policy between zones to permit the traffic  or configure "service-manage ping enable" under interfaces to solve this kind of issues.

Glad to help you! Any further questions, let us know.

View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.