%ASA-4-313005: No matching connection for ICMP error message:

Unanswered Question
Sep 27th, 2010
User Badges:

Hello Frdz ...


I have NTP server in DMZ zone and all Inside hosts would get syn with DMZ zone NTP server ..

I have been getting huge No matching connection for ICMP error message between inside host and DMZ NTP server ....

Could you please suggest how to stop this messages ...


Regards ..

Manik Palekar

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
manik.palekar Thu, 09/30/2010 - 08:03
User Badges:

Hi Jennifer ....


Thanks for the details ..at present these icmp requests are being blocked by Firewall due to No matching connection or there is no exiting icmp session .This results in top denied connection and which is causing high cpu and memory ..


would like to know if there any way to stop these sessions ..


Regards ..

Manik Palekar

Panos Kampanakis Thu, 09/30/2010 - 13:55
User Badges:
  • Cisco Employee,

Please enable "inspect icmp" and "inspect icmp error" and see if it helps.


If you have icmp inspection the FW will create conns per icmp pakcet that is see. Though if the response is coming from the wrong interface you will the "no connection" messages.


I would also suggest capturing the icmp packets on the FW interfaces if the icmp error persist.


PK

Actions

This Discussion