Dear ExpertsI have Checkpoint NG FP3 firewall with the three
interfaces with the following network structure.

internet ------1.firewall-2.---- 192.168.100.100 DMZ (StaticNAT)
`-3.------ 192.168.101.1 LAN

1.public_ip

Hosts using gateway of interface2 can able to access the resources of
intra+internet.My question is that how to make firewall rules so that
hosts using g/w of interface 3 can't able to ping 192.168.101.1?
Any suggestions is greatly appreciated.

Thanks
Balen.