In the MMC interface, right-click IP Security Policies on the Local Computer and select Create IP Security Policy .
Lock Ping traffic with IPSec Picture 11
In the Welcome screen, click Next
In the IP Security Policy Name , enter a descriptive name, such as " Block PING ". Click Next .
Lock Ping traffic with IPSec Picture 12
In the Request for Secure Communication window, uncheck the Active the Default Response Rule check box. Click Next .
Lock Ping traffic with IPSec Picture 13
In the Completing IP Security Policy Wizard window, click Finish .
Lock Ping traffic with IPSec Picture 14
We now need to add the various IP Filters and Filter Actionsto the new IPSec Policy . In the new IPSec Policy window, click Add to add IP Filters and Filter Actions
Lock Ping traffic with IPSec Picture 15
In the welcome window, click Next .
In Tunnel Endpoint , make sure that the default settings are selected and click Next .
Lock Ping traffic with IPSec Picture 16
In the Network Type window, select All Network Connections and click Next .
Lock Ping traffic with IPSec Picture 17
In the IP Filter List window, select " All ICMP Traffic " (or any IP Filter configured in step 5 above the article). If for some reason, you did not properly configure the IP Filter beforehand, you can click Add and add it at this time. When done, click Next .
Lock Ping traffic with IPSec Picture 18
In the Filter Action window select " Block ". Next, if you have not configured the right Filter Action before, you can click Add to add it now. When done, click Next .
Lock Ping traffic with IPSec Picture 19
Notice how to add IP Filter.
Lock Ping traffic with IPSec Picture 20
Next, you can add any combination of IP Filters and Filter Actions if you want.
Note that you cannot change their order like true firewalls. However this configuration works quite perfectly.
The next stage is to assign the IPSec Policy.
Assign IPSec Policy
In the MMC interface, right-click IPSec Policy and select Assign .
Lock Ping traffic with IPSec Picture 21
When done, you can test the configuration by trying to surf to a restricted and restricted website.
Lock multiple computers
Locking multiple computers can be done in two ways:
Export and Import IPSec Policy
Configure IPSec Policy through GPO
Both of these methods are used to prevent some computers from using ICMP (for other IPSec Policies).