Skip to main content

ejzy_t-wB713IaWlssBEWpQusaGXf-xM0z489kfdxTXRUu62eXpuczxJFlGht5JdO2p9wlAU1z2Ky8lzcyZVyYhmdEaVLrbODpBmTNnltLuQVMDUwuBcrcsl6bdni-LP-rmTeToyidnO-5L-uzocag

Netskope Global Technical Success (GTS)

KB - How to Allow/bypass ICMP traffic to a specific IP with Cloud Firewall

 

Netskope Cloud Version - 119

 

Objective

How to bypass ICMP traffic to a specific IP with Cloud Firewall.

 

Prerequisite

Netskope for Cloud Firewall license is required.

 

Context

Customers need to allow ICMP traffic to specific Network Locations.

 

Netskope Cloud Firewall

This document guides you to configure a use case related to the Netskope cloud firewall. The Netskope cloud firewall controls your organizations’ outbound non-HTTP(S) traffic. However, if you intend to manage the HTTP(S) traffic (on port 80/443 and non-standard ports), you can refer to the Netskope Secure Web Gateway and Netskope Cloud Access Security Broker documentation.

Please refer the following link to expand the information: Netskope Cloud Firewall

 

Use Case 1

Allow ICMP traffic to a specific IP with Cloud Firewall with a RTP policy.

 

Configuration

  • Step 1 - Create a Firewall App definition rule.

Path: Netskope Tenant UI >>> Settings >>> Security Cloud Platform >>> App definition >>> Cloud & Firewall Apps >>> New app definition rule >>> Select Firewall app

kvirRDz_Pbc_igZSJDL7wKzVupAA0w3lSdVCI-WB8cCV12HPEX0kjgznk0T5r4orr9PUVBwbWmo_looITo29oXUMWJl-DJKBFlv2hmzgxrbWTMRKz91JoxDUEG-9j3Mhy-1QEuDOq86hV2Nd4hE5-w


Add the destination IP needed to be reached with ICMP traffic, select the protocol= ICMP and assign a name to the app definition.

 

MafQUdqh4ct9E6Rmrj2ACN78D2ujsYuWW3Mp_ZX8J64vEJ7KpuqNDruvrz_TC7uSIkdQgWPBU4-3i3g5r9TGRNafvtrXNLxAWnOoB7qbTFTs8B3m_lyBucyvmrp69i98EBMx16l8SAoeFuWl47wcUg

 

  • Step 2 – Confirm all traffic steering config from the Steering configuration.

Path: Netskope Tenant UI >>> Settings >>> Security Cloud Platform >>> Steering configuration

Select the steering configuration where are the users you want to permit the traffic.

If the traffic is not set to all traffic click in the 3 dots and select and apply all traffic at cloud, web and firewall section.

4Oqr7Mfm3IUC8pk8DK69l6N5DRvQ0agy3wAlJQX1P1IIxoUowkv6141sJX6uzUDgx6d_msuL3ih8mQ500CAnpmat7h-tm8cfYBOJ_LhyLP_kNe5aJb7Ejkp-Ym7Fk0RgqyJUPrlLXdMMND3fCtBsJw

NwFcLGfgwV7-ID_6K_J-YDJ1et1V2yDVdVCu4gM729zZ2dOPrLvW7O_myPLhhBSEXqF0TiQjgQB-jGEz7Z43HUoYwKFLj2Co3dSDoA_N-OX4NhAj6QxGY5X-zSUM-U4UKioIbY5F9QkXsDdpShwpJA

  • Step 3 –  Create an RTP policy to allow the traffic.

Path: Netskope Tenant UI >>> Policies >>> Real-time Protection >>> New Policy >>> Firewall 

NgFkJucGCz5XyccxgB1v9F3IWPqAZxqtWaqfMpU6eC9W_IPZteBWZyfkoK_MungHTefo7QLzfg5PXIHelKhgA_UafQ1UMxMXh5LCtbV3E2uOz8gLb5qwCDzbdspx_1zq1gqN0cl4rAq1Oc7dzyhrgg

 

Select the Application Created in step1 and set action allow

RDdCh4RyvZ4G67eR08kcqqsZtZlwjWMGmk1R2oLPcmWT0aZljsNQDG4vcvqefSaHRGwUWNWQQ4HZPfIwKXzjMWeaQCRH55cWqcDuFHMH96uImeyLyNloZuv4s3K_O5BkI2jbSRKKuPL9K3466ENMCg

Click save and save changes.

 

Note

  1. Every time a change is applied, It is recommended to include “NOTES” for tracking purposes.
  2. Special Characters are not allowed in the policy name section.

 

Use Case 2

Bypass ICMP traffic to a specific IP with Cloud Firewall with a Steering Exception.

 

Configuration

Please follow steps 1 and 2 from Use Case 1.

Step 3 – Create Bypass Certificate Pinned Application Exception.

Path: Netskope Tenant UI >>> Settings >>> Security Cloud Platform >>> Steering Configuration

Select the steering configuration you want to apply the exception

Go to exceptions and Create a New Application Exception.

A screenshot of a computerDescription automatically generated

 

Select the application created at step 1 and click add.

A screenshot of a computerDescription automatically generated

 

This policy will bypass the ICMP traffic for the specific IPs configured.

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the default settings may be altered. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.