cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
536
Views
0
Helpful
5
Replies

Unable to ping from inside network to outside network

Hi, the ping initiated from inside network to outside hosts is dropping on outside interface. If i add acl entry to allow icmp on outside interface, ping is fin but this is asa 5540 (statefull firewall) that should remember connection initiated from inside network. This is production firewall used to allow internet surfing which works ok. Any idea where to start troublehoting would be greatly appreciated.

1 Accepted Solution

Accepted Solutions

5 Replies 5

acomiskey
Level 10
Level 10

It is not stateful for icmp traffic. You must explicitly allow it in an acl or enable icmp inspection. The ASA is acting as it should.

read this:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml

it covers both icmp and traceroute issues through your firewall.

Thank you gents.

I like ASA more and more..

Regards,

If you want to enable stateful ICMP inspection you can do this from global config

Type

policy-map global_policy

class inspection_default

inspect icmp

Thank you all for prompt response; i setup asa as per cisco's doc (15246) and it is OK now.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card