Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

IMCP Deny on oustide Interface

I have an ASA 5505. I need to ping from the inside interface 10.xx.70.1 to the outside xx.xxx.120.115. I have IGMP inspect going but still can not ping anything on the outside.

Can some one help me fix this

Thanks

mike

2 ACCEPTED SOLUTIONS

Accepted Solutions

Re: IMCP Deny on oustide Interface

Hi, Mike

Could you show the configuration.

I think it would the easiest way to help.

Green

Re: IMCP Deny on oustide Interface

access-list group-in_1 extended permit icmp any any

7 REPLIES

Re: IMCP Deny on oustide Interface

Have you configured NAT for the internal subnet 10.xx.70.0 ?

Community Member

Re: IMCP Deny on oustide Interface

Yes I have. Everything seems to be working I just can't ping from the inside to any device on the outside.

Mike

Re: IMCP Deny on oustide Interface

Hi,

I suggest to read the below article. It contains steps and configuration examples

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0

Community Member

Re: IMCP Deny on oustide Interface

Hello,

Thanks for the link. I have ICMP inspection tured on but when I ping I get

"Deny ICMP src inside 10.xx.180.5 dst outside xxx.xx.120.125 (type 8, code 0) by "access group-in_1" from the ASA.

Thanks

Mike

Re: IMCP Deny on oustide Interface

Hi, Mike

Could you show the configuration.

I think it would the easiest way to help.

Green

Re: IMCP Deny on oustide Interface

access-list group-in_1 extended permit icmp any any

Community Member

Re: IMCP Deny on oustide Interface

Thant did it thanks.

Mike

160
Views
0
Helpful
7
Replies
CreatePlease to create content