Information
Allows ICMP traffic for specific hosts or subnets and denies ICMP traffic for all other sources
Rationale:
ICMP is an important troubleshooting tool that can also be used to perform ICMP attacks on untrusted interfaces. For these interfaces, the ICMP traffic should be allowed only for specific hosts or subnets that are trusted by the Enterprise and should be denied for all other sources.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Configure ICMP using Firepower Management Center:
Step 1 - Select Devices > Platform Settings and create or edit a FTD policy
Step 2 - Select ICMP.
https://www.cisco.com/c/en/us/td/docs/security/firepower/621/configuration/guide/fpmc-config-guide-v621/platform_settings_for_firepower_threat_defense.html#task_42BBA666CD604517ADA18B32CA162F62