Unable to ping from inside network to outside network

Answered Question
May 16th, 2008

Hi, the ping initiated from inside network to outside hosts is dropping on outside interface. If i add acl entry to allow icmp on outside interface, ping is fin but this is asa 5540 (statefull firewall) that should remember connection initiated from inside network. This is production firewall used to allow internet surfing which works ok. Any idea where to start troublehoting would be greatly appreciated.

I have this problem too.
0 votes
Correct Answer by srue about 8 years 5 months ago

read this:


it covers both icmp and traceroute issues through your firewall.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (1 ratings)
acomiskey Fri, 05/16/2008 - 08:42

It is not stateful for icmp traffic. You must explicitly allow it in an acl or enable icmp inspection. The ASA is acting as it should.

vabruno Mon, 05/19/2008 - 17:39

If you want to enable stateful ICMP inspection you can do this from global config


policy-map global_policy

class inspection_default

inspect icmp

Dragan Milojevic Tue, 05/20/2008 - 13:55

Thank you all for prompt response; i setup asa as per cisco's doc (15246) and it is OK now.


This Discussion