<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>RESOLVED: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/utm-firewall/unified-threat-management-beta/utm_94_beta/f/sophos-utm-9-4-public-beta/74666/resolved-ipv6-and-icmp-packets-with-utm</link><description>Hi, 
 
 There appears to be a bug with the UTM and IPv6 - these options do not function as they should. 
 
 I have to unstick everything in the firewall &amp;gt; ICMP settings in order to stop ICMP getting through the firewall. 
 
 I would have expected that</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: RESOLVED: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/289380?ContentTypeID=1</link><pubDate>Fri, 04 Mar 2016 02:01:19 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:146c9753-9c97-44d1-bebf-f4e1ab7a8945</guid><dc:creator>dontpanic</dc:creator><description>&lt;p&gt;Nice to hear that.&amp;nbsp;[:)]&lt;br /&gt;That&amp;#39;s how it should look like, if you don&amp;#39;t allow ping or ICMP in general through your Uplink interface.&lt;/p&gt;
&lt;p&gt;Yeah, I work for Sophos in QA. There were some problems with the migration from the old astaro forum to this forum and maybe someone forgot to put me on the &amp;quot;Sophos Staff&amp;quot; list.&lt;/p&gt;
&lt;p&gt;However it&amp;#39;s nice that your issue doesn&amp;#39;t occur anymore. :)&lt;/p&gt;
&lt;p&gt;/Daniel&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/289354?ContentTypeID=1</link><pubDate>Thu, 03 Mar 2016 16:07:38 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b420dfb3-57dd-40a3-a5f5-75b8bdcd79f5</guid><dc:creator>BLS</dc:creator><description>&lt;p&gt;I come bearing good news! &amp;nbsp;Just installed the latest 9.4 Beta 2 and ppp0 is included in the &amp;quot;ip6tables -vnL AUTO_FORWARD&amp;quot; result!&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_03_2D00_03-at-10.04.07-PM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_03_2D00_03-at-10.04.07-PM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Thank you for your assistance in getting this resolved - on with the next one which is IPv6 and the Web-Filter (Have listed it here).&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;If you need any assistance with the IPv6 / WebFilter let me know and I&amp;#39;ll do what I can to assist, BTW didn&amp;#39;t realize you were Sophos Staff...&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;/Tim&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/289120?ContentTypeID=1</link><pubDate>Wed, 02 Mar 2016 04:03:23 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cab65fd6-b003-49b5-b3c8-a4f11b425e1d</guid><dc:creator>BLS</dc:creator><description>&lt;p&gt;More than happy to assist with debugging, let me know what you need me to do this end and more than happy to run and post the output.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288726?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 10:30:17 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7a338307-596d-437e-9cd2-6d8ce61e12f2</guid><dc:creator>dontpanic</dc:creator><description>&lt;p&gt;I opened a ticket for the issue.&lt;/p&gt;
&lt;p&gt;Thanks a lot for the effort and the patience!&amp;nbsp;[:)]&lt;/p&gt;
&lt;p&gt;Would it be possible to get ssh access for debugging next week?&lt;/p&gt;
&lt;p&gt;/Daniel&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288722?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 10:05:45 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:61e89e55-7dad-4aee-bfcb-f2fa7730291e</guid><dc:creator>BLS</dc:creator><description>&lt;p&gt;Just thought I would try something out the box.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Took a copy of the config for my UTM, built a new isolated VM and restored the configuration - still getting the same results as I was previously.&lt;/p&gt;
&lt;p&gt;Changed the external interface from PPPoE to Ethernet, and voila - getting the drop ICMPv6 eht0 rule - changed back to PPPoE and it&amp;#39;s gone!&lt;/p&gt;
&lt;p&gt;So this looks like it&amp;#39;s a PPPoE bug.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288719?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 09:52:18 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7c13f493-c560-4b7c-8b0f-4927d982d63a</guid><dc:creator>dontpanic</dc:creator><description>&lt;p&gt;The options in the ICMP tab overrule the firewall rules in&amp;nbsp;Network Protection &amp;gt;&amp;gt;&amp;nbsp;Firewall &amp;gt;&amp;gt; Rules. But if you uncheck the options in the ICMP tab there are no rules for ICMP anymore on the system which means the firewall rules could match the traffic.&lt;/p&gt;
&lt;p&gt;Is it possible to get ssh access to your machine? That would be really helpful and would speed it up. :)&lt;br /&gt; Unfortunately I can&amp;#39;t reproduce your issue and the packetfilter rules should contain a DROP rule which isn&amp;#39;t the case for you.&lt;/p&gt;
&lt;p&gt;For me it looks like this on the shell (with eth0 as default gw):&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/iptables.png"&gt;&lt;img src="/resized-image/__size/940x0/__key/communityserver-discussions-components-files/140/iptables.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;/Daniel&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288713?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 09:09:38 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:39757b4c-2b30-4ff1-992f-a23fa7a0d975</guid><dc:creator>BLS</dc:creator><description>&lt;p&gt;I do have a any internal to any external rule - guess that&amp;#39;s picking up ICMP - but I would have thought that the firewall would have applied the ICMP rules first?? &amp;nbsp;Maybe inthis case it&amp;#39;s not.&lt;/p&gt;
&lt;p&gt;All results where I&amp;#39;m told that it&amp;#39;s either reachable or filtered are from external to internal&lt;/p&gt;
&lt;p&gt;I did create a from external to internal drop ICMP for IPv6 rule, that also made no difference, the settings in the ICMP tab overruled what was in the firewall settings.&lt;/p&gt;
&lt;p&gt;This is the&amp;nbsp;ip6tables -vnL AUTO_FORWARD results, with just &amp;nbsp;Allow ICMP through gateway selected.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-3.05.10-PM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-3.05.10-PM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;This is the&amp;nbsp;cc get icmp results&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-3.05.49-PM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-3.05.49-PM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;With&amp;nbsp;Gateway forwards pings selected only.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-3.12.36-PM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-3.12.36-PM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;And with only the &amp;quot;Allow ICMP through Gateway from external networks&amp;quot; option selected.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-3.09.22-PM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-3.09.22-PM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288707?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 07:55:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0f332ccf-24ee-4e7d-99ea-29cdd1102269</guid><dc:creator>dontpanic</dc:creator><description>&lt;p&gt;You are right. With your last two pictures you should only be able to ping from the UTM itself but not through the UTM from internal to external.&lt;/p&gt;
&lt;p&gt;Do you have any firewall rules configured in&amp;nbsp;Network Protection &amp;gt;&amp;gt; Firewall &amp;gt;&amp;gt; Rules?&lt;/p&gt;
&lt;p&gt;Those could match ICMP traffic as well, if you don&amp;#39;t explicit allow the traffic in the ICMP tab.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Regarding the second to the last post:&lt;/p&gt;
&lt;p&gt;Could you do me a favor and provide me the output of the following commands for the &amp;quot;reachable&amp;quot; cases?&lt;/p&gt;
&lt;p&gt;#&amp;nbsp;ip6tables -vnL AUTO_FORWARD&lt;/p&gt;
&lt;p&gt;#&amp;nbsp;cc get icmp&lt;/p&gt;
&lt;p&gt;I assume you tried to ping from external to internal, right?&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Thanks a lot!&lt;/p&gt;
&lt;p&gt;/Daniel&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288695?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 05:59:16 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6883be38-829d-4d90-b65c-96ecc9cd56fb</guid><dc:creator>BLS</dc:creator><description>&lt;p&gt;And even more strange.....&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.56.43-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.56.43-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/0458.Screen-Shot-2016_2D00_02_2D00_26-at-11.58.48-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/0458.Screen-Shot-2016_2D00_02_2D00_26-at-11.58.48-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Surely with all these options deselected I shouldn&amp;#39;t be able to ping an external IP from internal?&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Tim&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288693?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 05:54:09 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c59f309a-407f-4d92-b5da-f395cd47ef43</guid><dc:creator>BLS</dc:creator><description>&lt;p&gt;I&amp;#39;m confused - surely with &amp;quot;&lt;b&gt;Allow ICMP through gateway&lt;/b&gt;&amp;nbsp;enabled, there should be no WAN to LAN ICMP, as described in the help &amp;quot;&lt;b&gt;Allow ICMP through gateway&lt;/b&gt;&amp;nbsp;will make the system forward ICMP traffic if originating from an internal network..&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;These are the results per different configuration of the ICMP section - does this seem correct to you?&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.46.20-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.46.20-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Result:&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.46.46-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.46.46-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Configuration: -&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.50.58-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.50.58-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Result: -&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.51.22-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.51.22-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Configuration:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.52.25-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.52.25-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Result:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.52.02-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.52.02-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Configuration&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.53.28-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.53.28-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Result&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.53.35-AM.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/140/Screen-Shot-2016_2D00_02_2D00_26-at-11.53.35-AM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288677?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 04:13:28 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:84e56bd8-b800-4ce5-b5e6-9fce22a305ae</guid><dc:creator>dontpanic</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;xnsys,&lt;/p&gt;
&lt;p&gt;If you have &amp;quot;Allow ICMP through Gateway from external networks&amp;quot; enabled, you explicitly allow ICMP traffic from external to internal networks. To forbid this you have to uncheck&amp;nbsp;&amp;quot;Allow ICMP through Gateway from external networks&amp;quot; and you have to enable &amp;quot;Gateway forwards pings&amp;quot; for example. Then the DROP rule should be written.&lt;/p&gt;
&lt;p&gt;You described the correct behavior with both enabled:&amp;nbsp;&amp;quot;Allow ICMP through Gateway from external networks&amp;quot; &amp;nbsp;and&amp;nbsp;&amp;quot;Gateway forwards pings&amp;quot;.&lt;/p&gt;
&lt;p&gt;/Daniel&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288667?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2016 03:05:06 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5374bf32-380d-4c3d-aba8-7e300620a8fe</guid><dc:creator>BLS</dc:creator><description>&lt;p&gt;Just got loads of this repeated in the middleware logs - nothing that looks like an error to me.&lt;/p&gt;
&lt;pre&gt;2016:02:26-08:36:10 phobos middleware[3782]: T main::top-level:275() =&amp;gt; cycle 838 waiting for 1 children
2016:02:26-08:36:30 phobos middleware[3782]: T main::top-level:264() =&amp;gt; ending cycle 838, caught 1 signals, 1 children still running
2016:02:26-08:36:30 phobos middleware[3782]: T main::top-level:213() =&amp;gt; starting cycle 839, caught 1 signals
2016:02:26-08:36:30 phobos middleware[3782]: T core::Config::Changed:194() =&amp;gt; configversion=937
2016:02:26-08:36:30 phobos middleware[3782]: T core::Config::Changed:204() =&amp;gt; nodes=0 objects=1 triggers=0
2016:02:26-08:36:30 phobos middleware[3782]: T core::Config::load:347() =&amp;gt; modules=2,10
2016:02:26-08:36:30 phobos middleware[3782]: T modules::up2date::load:108() =&amp;gt; amazon_deployment_type=
2016:02:26-08:36:30 phobos middleware[3782]: T modules::up2date::setAll:240() =&amp;gt; up2date setAll
2016:02:26-08:36:30 phobos middleware[3782]: T modules::ipset::deleteUnused:320() =&amp;gt; auto#=3/682 confd#=1/341
2016:02:26-08:36:30 phobos middleware[3782]: T main::top-level:275() =&amp;gt; cycle 839 waiting for 2 children
2016:02:26-08:36:32 phobos middleware[3782]: T main::top-level:275() =&amp;gt; cycle 839 waiting for 1 children&lt;/pre&gt;
&lt;p&gt;Result of &amp;nbsp;&lt;span style="font-family:&amp;#39;courier new&amp;#39;, courier;"&gt;ip6tables -vnL AUTO_FORWARD&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left:30px;"&gt;&lt;span style="font-family:&amp;#39;courier new&amp;#39;, courier;"&gt;Chain AUTO_FORWARD (1 references)&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left:30px;"&gt;&lt;span style="font-family:&amp;#39;courier new&amp;#39;, courier;"&gt;&amp;nbsp;pkts bytes target &amp;nbsp; &amp;nbsp; prot opt in &amp;nbsp; &amp;nbsp; out &amp;nbsp; &amp;nbsp; source &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; destination&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left:30px;"&gt;&lt;span style="font-family:&amp;#39;courier new&amp;#39;, courier;"&gt;&amp;nbsp; &amp;nbsp; 0 &amp;nbsp; &amp;nbsp; 0 STRICT_TCP_STATE&amp;nbsp; tcp&amp;nbsp; &amp;nbsp; &amp;nbsp; *&amp;nbsp; &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; ::/0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ::/0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ctstate INVALID,NEW&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left:30px;"&gt;&lt;span style="font-family:&amp;#39;courier new&amp;#39;, courier;"&gt;&amp;nbsp; &amp;nbsp; 0 &amp;nbsp; &amp;nbsp; 0 CONFIRMED&amp;nbsp; icmpv6&amp;nbsp; &amp;nbsp; *&amp;nbsp; &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; ::/0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ::/0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipv6-icmptype 128 code 0&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left:30px;"&gt;&lt;span style="font-family:&amp;#39;courier new&amp;#39;, courier;"&gt;&amp;nbsp; &amp;nbsp; 0 &amp;nbsp; &amp;nbsp; 0 CONFIRMED&amp;nbsp; icmpv6&amp;nbsp; &amp;nbsp; *&amp;nbsp; &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; ::/0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ::/0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipv6-icmptype 129 code 0&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Just checked again, disabled the windows firewall on the local machine, with&amp;nbsp;Allow ICMP through Gateway from external networks enabled, ICMP doesn&amp;#39;t reach the internal machine, with&amp;nbsp;Gateway forwards pings enabled, the local machine receives the packets, and responds to ICMP.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288439?ContentTypeID=1</link><pubDate>Wed, 24 Feb 2016 04:04:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e7d6d1c7-7c8e-4e99-89f1-dd7880403488</guid><dc:creator>dontpanic</dc:creator><description>I really cannot reproduce your issue. :/&lt;br /&gt;
Could you open Webadmin and go to Logging &amp;amp; Reporting &amp;gt;&amp;gt; View Log Files and check, if you find any errors in the MiddleWare?&lt;br /&gt;
&lt;br /&gt;
I just checked if the ip6tables rule is written for a PPPoE interface and it worked. Do you have ssh access to your machine? Maybe you could verify, if the iptables rule is present for you as well.&lt;br /&gt;
Just disable &amp;quot;Allow ICMP through Gateway from external networks&amp;quot; and enable &amp;quot;Gateway forwards pings&amp;quot;.&lt;br /&gt;
Connect to your UTM via ssh and execute this command:&lt;br /&gt;
# ip6tables -vnL AUTO_FORWARD&lt;br /&gt;
&lt;br /&gt;
You should find a DROP rule pinned to a ppp device (e.g. ppp0).&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288337?ContentTypeID=1</link><pubDate>Tue, 23 Feb 2016 04:43:50 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:25a4c552-1e92-4456-a035-a5e17fae9a55</guid><dc:creator>BLS</dc:creator><description>I only have 2 interfaces, external PPPoE and Internal.&lt;br /&gt;
&lt;br /&gt;
It&amp;#39;s a very simple set-up with the UTM acting as a perimeter firewall.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288336?ContentTypeID=1</link><pubDate>Tue, 23 Feb 2016 04:35:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d688e65e-ed86-43a9-9328-7c2e44b265ec</guid><dc:creator>dontpanic</dc:creator><description>I tried the &amp;quot;Allow ICMP through Gateway from external networks&amp;quot; option in combination with &amp;quot; Allow ICMP through gateway&amp;quot; and &amp;quot;Gateway forwards pings&amp;quot; and it works as expected for me.&lt;br /&gt;
Whenever I unchecked &amp;quot;Allow ICMP through Gateway from external networks&amp;quot; the ping6 packets are not forwarded from WAN to LAN anymore.&lt;br /&gt;
&lt;br /&gt;
Could you show / explain how your Interfaces are configured? Where are your icmp6 packets come from and where do they go?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/288047?ContentTypeID=1</link><pubDate>Sat, 20 Feb 2016 01:50:55 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ddec629e-b2e1-462c-9387-42ec1b738e96</guid><dc:creator>BLS</dc:creator><description>The problem is not ICMP packets going from the LAN to WAN, it&amp;#39;s the other way round.&lt;br /&gt;
&lt;br /&gt;
It works fine for IPv4, but not IPv6.&lt;br /&gt;
&lt;br /&gt;
The firewall is allowing LAN machines to be pinged from the WAN, despite unchecking the &amp;quot;Allow ICMP through Gateway from external networks&amp;quot; option - surely this would mean that internal machines are not visible to ICMP?&lt;br /&gt;
&lt;br /&gt;
If you have any other option ticked, then there is no change in function with the &amp;quot;Allow ICMP through Gateway from external networks&amp;quot; option - it will always allow packets from the WAN to LAN via IPv6.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/287802?ContentTypeID=1</link><pubDate>Thu, 18 Feb 2016 03:19:56 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3ccb6ad0-7904-4ba7-877d-cda4977f8876</guid><dc:creator>dontpanic</dc:creator><description>Hi xnsys,&lt;br /&gt;
&lt;br /&gt;
It&amp;#39;s true, that ping packets are allowed, if you enable &amp;quot;Gateway forwards trace route&amp;quot;. It has technical reasons and is documented in the Onlinehelp:&lt;br /&gt;
&amp;quot;Note – If enabled, the traceroute settings also allow ping packets, even if the corresponding ping settings are disabled.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
I&amp;#39;m not sure if I understand the problem with &amp;quot;Allow ICMP through Gateway from external networks&amp;quot;. If you select and apply the option, you allow ICMP packets going through interfaces with default gateways. (the interface must be the incoming interface)&lt;br /&gt;
If you don&amp;#39;t select the option, you can&amp;#39;t send ICMP packets through interfaces with default gateways.&lt;br /&gt;
&lt;br /&gt;
At least one of the following options must be enabled so that &amp;quot;Allow ICMP through Gateway from external networks&amp;quot; works:&lt;br /&gt;
* Allow ICMP through gateway&lt;br /&gt;
* Gateway forwards pings&lt;br /&gt;
* Gateway forwards traceroute&lt;br /&gt;
&lt;br /&gt;
/Daniel&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: BUG: IPv6 and ICMP packets with UTM</title><link>https://community.sophos.com/thread/287422?ContentTypeID=1</link><pubDate>Mon, 15 Feb 2016 01:04:44 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:bb8e83ee-34a7-4b8f-a612-d52afcf3bbcf</guid><dc:creator>HolgerLehn</dc:creator><description>&lt;p&gt;_&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>