We have two private subnets protected with ASA5505s. A poorly written application using ICMP and FTP produces NOOP packets and understandibly the Firewalls drop this traffic. Is it possible to configure the ASA5505 temporarily to confirm the problem we have with the App? I know its possible to configure a PIX for this.
You can open up icmp in the inside and outisde ACLs to and from the ftp server and allow all ip traffic from the FT server.
Then disable the ftp and icmp inspection.
Try again to see if the app works.
I hope it helps.
PK
Getting Started
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: