cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
289
Views
0
Helpful
5
Replies

ASA's outsode interface can be "pinged" should it be?

whiteford
Level 1
Level 1

Hi, from the Internet I can ping our ASA's outside interface, should this be liek if not how can I stop it?

5 Replies 5

abinjola
Cisco Employee
Cisco Employee

yes by default its allowed

Add this to block :-

ASA5510-Single(config)# icmp deny any echo outside

Does it matter if it's "pingable" or should it locked down?

I only use the ASDM and added the rule at the top of the list as a deny and I could still ping outside interface?

well sometimes you might need to allow pings to outside Interface for troubleshooting purpose...so there is not harm to allow excho request to outside Interface, moreover if your ICMP has configured rate limiting on ICMPs then you don't need to worry about the flood hitting ASA

In ASDM you might have added rule in ACL to deny this but this isn't a transitting traffic so ACL does not work for this

How do I configured rate limiting on ICMP's?

Andy , you may want to try icmp deny any outside

Jorge Rodriguez
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card