Information
This drops the out of state ICMP packets.
Rationale:
The Firewall verifies that each ICMP reply packet matches a previous request, and each ICMP error matches an existing connection. Out of State ICMP packets should be dropped and logged.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Go to the following path and checked the Drop Out of State ICMP Packets and Log on Drop.
SmartConsole > Global Properties > Stateful Inspection
Checked the Drop Out of State ICMP Packets and Log on Drop
Default Value:
Enabled