05-16-2008 08:39 AM - edited 03-11-2019 05:46 AM
Hi, the ping initiated from inside network to outside hosts is dropping on outside interface. If i add acl entry to allow icmp on outside interface, ping is fin but this is asa 5540 (statefull firewall) that should remember connection initiated from inside network. This is production firewall used to allow internet surfing which works ok. Any idea where to start troublehoting would be greatly appreciated.
Solved! Go to Solution.
05-16-2008 11:30 AM
read this:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml
it covers both icmp and traceroute issues through your firewall.
05-16-2008 08:42 AM
It is not stateful for icmp traffic. You must explicitly allow it in an acl or enable icmp inspection. The ASA is acting as it should.
05-16-2008 11:30 AM
read this:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml
it covers both icmp and traceroute issues through your firewall.
05-16-2008 12:26 PM
Thank you gents.
I like ASA more and more..
Regards,
05-19-2008 05:39 PM
If you want to enable stateful ICMP inspection you can do this from global config
Type
policy-map global_policy
class inspection_default
inspect icmp
05-20-2008 01:55 PM
Thank you all for prompt response; i setup asa as per cisco's doc (15246) and it is OK now.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: