we are using a ASA 5540 with 3 Interfaces. Version 8.2(1)
One interface is Inside, one Outside and one interface is the DMZ.
1. Is it possible to configure the ASA, to send icmp unreachable messages, if one Server in the DMZ is down.
At the moment we are having Problems, because of the Timouts. The Programms hang for a llong time.
What do we have to configure?
2. At many Firewalls it is possible to differentiate between drop and reject. At some ACLs we want the ASA to send back an
"Communication administratively prohibited". Is it possible to configure this?
Thanks in advance.
I see now. The firewall will not respond to unreachable hosts with a ICMP unreachable since the firewall is suppose to be invisble. Currently there is no way to enable the firewall to send icmp unreachables. You can make a feature request with your Cisco Account team to see if this is something the firewall team can consider.