Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

External Pings

I would like to be able to ping our WAN interface from specific external IPs, but the only thing I am seeing I can do currently is allow Ping/Ping6 via the ACLs (Administration > Device Access > Local Service ACLs).  When doing so, this seems to open it up to every external IP.  I tried creating a simple firewall rule to allow ICMP to the WAN interface, but it didn't seem to do anything. Am I missing something?



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thank you for contacting the Sophos Community.

    1. Under Local Sevice ACL, you need to leave the Ping/Ping6 Disable for the WAN zone

    2. Under Local Service ACL Exception rule create a rule like this:

    Source Zone = WAN

    Source Network/Host = Public IP from where you are going to be Pinging  the Sophos XG

    Destination Host = ANY

    Services = Ping

    Action = Accept

    That should allow you to Ping the XG only from that specific IP.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Reply
  • Hello there,

    Thank you for contacting the Sophos Community.

    1. Under Local Sevice ACL, you need to leave the Ping/Ping6 Disable for the WAN zone

    2. Under Local Service ACL Exception rule create a rule like this:

    Source Zone = WAN

    Source Network/Host = Public IP from where you are going to be Pinging  the Sophos XG

    Destination Host = ANY

    Services = Ping

    Action = Accept

    That should allow you to Ping the XG only from that specific IP.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Children
No Data