Re: ext vip address showing for internal pings you may want to change your nat rule as follows, as i suspect your local fw interface is included as part of your local network object? source destination localnet localnet(negated) then hide behind the ext int |