ER605 Block ping from WAN

ER605 Block ping from WAN

ER605 Block ping from WAN
ER605 Block ping from WAN
a week ago - last edited Friday
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.3

Hello

 

I want to ask about "Block ping from WAN" function in FireWall section (ER605 HW v2.20 latest firmware 2.3.3).

The box is checked and I can't ping my WAN and that's OK.

When uncheck box and save, I can ping my WAN and that's OK.

When I try to check box again to block ping from WAN and save I can still ping my WAN :(

After reboot everything is OK, ping from WAN is blocked.

Is it normal that uncheck box allow ping without reboot (immediately) but checking box again doesn't block ping from WAN right away? (till reboot).

Checked with Omada controller and ER605 in standalone mode and the same behavior.

I didn't check other options in FireWall section.

 

Is it bug or normal behavior (feature).

 

Thank you for explanation.

  0      
  0      
#1
Options
1 Accepted Solution
Re:ER605 Block ping from WAN-Solution
Friday - last edited Friday

  @KajtekKajtek 

We tested locally: after re-enabling “Loock Ping from WAN,” we waited two minutes and then pinged the WAN address; the ping failed, but we could not reproduce the issue you reported.
If you can reproduce it consistently, please re-enable the option, wait two minutes, capture a mirror packet trace, and verify whether the ICMP packets actually reach the WAN interface.How to capture packets using Wireshark on SMB router or switch

Recommended Solution
  0  
  0  
#4
Options
3 Reply
Re:ER605 Block ping from WAN
Wednesday - last edited Wednesday

  @KajtekKajtek 

After re-enabling it, wait a few minutes and then try pinging the WAN again to see if it still responds.

  0  
  0  
#2
Options
Re:ER605 Block ping from WAN
Wednesday

  @Ethan-TP 

I've waited 38 minutes :( Didn't work. Ping isn't blocked again. Only after reboot.

  0  
  0  
#3
Options
Re:ER605 Block ping from WAN-Solution
Friday - last edited Friday

  @KajtekKajtek 

We tested locally: after re-enabling “Loock Ping from WAN,” we waited two minutes and then pinged the WAN address; the ping failed, but we could not reproduce the issue you reported.
If you can reproduce it consistently, please re-enable the option, wait two minutes, capture a mirror packet trace, and verify whether the ICMP packets actually reach the WAN interface.How to capture packets using Wireshark on SMB router or switch

Recommended Solution
  0  
  0  
#4
Options