Originally posted here by Wilykiote
You can use IPSec rules to allow IMCP internally and deny ICMP-ECHO replies externally. This will still allow pinging inside the network itself.

Grumble, how did I gt this in the wrong thread?