Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fionaC
New Contributor II

Disabling ICMP Timestamp Replies from FortiAP on LAN

Does anyone know how to disable ICMP timestamp replies from FortiAPs? My FortiAPs are connected to my LAN, and I have Fortiswitches. Polices do not seem to work - my guess is because the traffic is being routed by the switches and not going through the firewall? 

5 REPLIES 5
AEK
SuperUser
SuperUser

If I'm not wrong the an ICMP timestamp reply is a response to an ICMP timestamp request, right?

In that case then you just need to add a firewall rule to deny ICMP requests from the desired source to the FortiAPs.

This is because I don't know a way to allow ICMP requests and in the same time to deny ICMP replies. As far as I know this is how stateful firewalls are designed.

AEK
AEK
fionaC
New Contributor II

For some reason, that does not work. I am wondering if it is because the APs and the host are on the same LAN, and therefore the traffic is not routed through the Fortigate.

Toshi_Esumi

It wouldn't go through the FGT. It's directly sent to AP by MAC address found in ARP.

Toshi

AEK
SuperUser
SuperUser

Then I guess it is possible just by disabling the ping on the related SSID interface.

AEK
AEK
Toshi_Esumi

I think it's about FAP's management interface, not SSIDs.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors