This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't ping across subnets.

I can't ping from the UTM to another internal subnet, and vice versa, even though the two subnets are fully routed and other devices on the network can ping each other.  Thanks.



This thread was automatically locked due to age.
Parents
  • Not a lot to go on here, but is ping allowed through the UTM firewall between subnets? Whats your logs telling you?

  • Sorry for lack of info--I'm configuring the appliance only for Spam filtering and email encryption--none of the other firewall services are in place. I am testing the UTM in between the firewall and the mail server, as a replacement for our current Sendio appliance.  The 2 networks are 192.168.1.x and 192.168.100.x.  The UTM is on the 192.168.1.x network, and can't ping any .100 addresses (they can't ping the UTM as well).

    Thank you,

  • Pretty sure you're going to run into some default firewall settings anyway. Check the ICMP settings on the firewall - advanced page. 

    Your last statement  "The UTM is on the 192.168.1.x network, and can't ping any .100 addresses (they can't ping the UTM as well)." But earlier you said "the two subnets are fully routed and other devices on the network can ping each other."

    Nothing makes sense. Anyway, check ICMP through gateway and Gateway forwards pings. Or, the logs tell you everything you'll need to know instead of us shooting in the dark

  • Somehow my reply from yesterday was lost....

    I have checked everything under ICMP, but stillno luck.  What I meant by "fully routed" is that all other devices on the network can see and ping other devices between subnets.  The UTM is the only device having a problem.

    Thanks,

  • James, there are two tricks here.  One is that the "Any" Service does not include ICMP, specifically not Ping, and the other is that you need firewall rules to regulate ping traffic between networks.  Any better luck now?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • There were no defined firewall rules (I presumed it would be open), but I created one to address both ping and https. Here are the current settings for both ICMP and the firewall rule (baptist homes is 192.168.1.0 /24, Providence Point is 192.168.100.0 /24).  Still no luck, thanks.

Reply
  • There were no defined firewall rules (I presumed it would be open), but I created one to address both ping and https. Here are the current settings for both ICMP and the firewall rule (baptist homes is 192.168.1.0 /24, Providence Point is 192.168.100.0 /24).  Still no luck, thanks.

Children