> Source: [sk179915](https://support.checkpoint.com/results/sk/sk179915)

# sk179915 - ICMP traffic passes on a rule without an explicit ICMP accept rule

| Property | Value |
|----------|-------|
| Solution ID | sk179915 |
| Date Created | 2022-09-01 |
| Last Modified | 2022-09-03 |
| Technical Level | General |
| Products | Other |
| Versions | Not Version-Specific |
| OS | Gaia |

## Symptoms

- * ICMP traffic passes on a rule without an explicit ICMP accept rule.

* The 'accept' log under matched rules shows 'implied rule- accept ICMP'.

* The matched rule seems to be an inline layer rule (for example rule number 2.0).

## Cause

If an inline layer rule matches traffic, it will also apply the implied rules.

In this case, the accept ICMP implied rule set to 'before last' was applied.

Note that the 'accept icmp' implied rule lists the ICMP types that it supports. It does not list ICMPv6 as this is only in the GUI. The rule also includes ICMPv6 requests which are not presented in the GUI.

## Solution

No fix is required. This behavior is by design.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
