HI There, You're creating the rule in the wrong spot this is a device access rule. You'll need to create a device access ACL under System >Administration > Device Access It'll need to look similar to below. I tried that and it worked for me. The test at website pulse does not appear to be accurate. I just use a ping test on both UTM and XG that had ICMP disable and website pulse reported a response when from any other device I was getting no response back. I then ran the test using CA's tool https:/asm.ca.com/en/ping.php and got the accurate/desired outcome.
↧