After upgrading from SEP 14.3 RU10 to SEP 16 you notice that ICMP traffic gets blocked unexpectedly. When attempting to Remote Desktop (RDP) from a system a different subnet to another host you notice it no longer works.
Symantec Endpoint Protection 16 (SEP 16)
Endpoint Security Agent (ESA) v2.8.0.31
Symantec Endpoint Security (SES)
The default firewall policy for SEP 16 agents blocks ICMP type 3 packets unexpectedly because there is no firewall rule to allow this traffic.
This is a known issue and we will address this in a future release.
Workaround:
Add a temporary Allow All rule for ICMP traffic (Type 3, Code 4) at the top of your firewall rules list and save your changes.
CRE-24142