When configuring a rule to detect ICMP echo replies (type 0, code 0), the rule does not work. Rules to detect ICMP echo requests (type 8, code 0) work as expected.
Resolving the problem
This is a known defect with no current resolution. Echo replies are associated with their respective requests. A rule matching echo requests will also match echo replies, since they are treated as related packets in a single flow.
If the above information does not resolve your issue, please contact IBM Security Systems Customer Support.