Let's go in steps: - from the LAN hosts I block all ICMP packets to the OPT1 hosts. - from the OPT1 hosts I block all ICMP packets to the hosts of LAN - I apply the rules - firewall -> diagnostics -> states -> actions -> reset state tableAfter that the rules work.Unexpected behavior, however, when I want to re-enable ICMP packet transit. - from the LAN hosts I allow all ICMP packets to the OPT1 hosts - from the OPT1 hosts I allow all ICMP packets to the hosts of LAN. - I apply the rulesAt this point only one of the two works. I have now made 5 attempts as described and the ping works 4 times for LAN and 1 time for OPT1. Almost like it was a random thing.Forgive me, this sounds strange, but it is happening.Gianluca