ERROR: access-list has icmp type selector

Answered Question
Jul 2nd, 2013
User Badges:

Hi all

im trying to apply access list to crypto map . and when i apply it its giving me the error

ERROR: access-list has icmp type selector


any idea please . thanks all

Correct Answer by Andrew Phirsov about 4 years 1 month ago

The crypto-acl should be of permit IP type. You shouldn't specify protocols, like ICMP, tcp, etc.


So your proxy-acl should looks smth like this:

access-list PROXY_ACL permit IP x.x.x.x 255.255.255.9 y.y.y.y 255.255.255.0

but not this:

access-list PROXY_ACL permit icmp host x.x.x.x host y.y.y.y eq echo

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Eduardo Aliaga Tue, 07/02/2013 - 23:02
User Badges:
  • Silver, 250 points or more

Please elaborate the question. What device (router or ASA) are you talking about and what version? could you show us the exact commands you applied when you got the error ?

Correct Answer
Andrew Phirsov Wed, 07/03/2013 - 04:53
User Badges:
  • Silver, 250 points or more

The crypto-acl should be of permit IP type. You shouldn't specify protocols, like ICMP, tcp, etc.


So your proxy-acl should looks smth like this:

access-list PROXY_ACL permit IP x.x.x.x 255.255.255.9 y.y.y.y 255.255.255.0

but not this:

access-list PROXY_ACL permit icmp host x.x.x.x host y.y.y.y eq echo

Ahmed Al jawad Thu, 07/11/2013 - 07:00
User Badges:

thanks Andrew . this is great help . still have problem the phase 2 tunnel is dropping on some networks . i will start new discussion for it . thanks agine

Shaoqin Li Wed, 07/03/2013 - 09:38
User Badges:
  • Bronze, 100 points or more

Andrew is correct

Sent from Cisco Technical Support iPhone App

Actions

This Discussion