Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

Any good ICMP from the Internet?

I was curious...Do any of you allow any type of ICMP traffic from the Internet? Maybe from your ISP only? Or does everyone deny all ICMP traffic from the Internet?

Thanks.

2 REPLIES
Community Member

Re: Any good ICMP from the Internet?

I typically only explicitly deny icmp echo on the outside interface. I believe that unless it's return traffic from and established connection or you have an access list explicitly permitting it, all other (icmp) traffic is denied.

Community Member

Re: Any good ICMP from the Internet?

Some ICMP traffic is needed, such as MTU discovery... But that's more appropriate if you're an enclave within an enclave - if you have a firewall between departments.

I specifically deny ICMP ECHO and Trace Route between Trusted subnets, then allow all other ICMP.

97
Views
0
Helpful
2
Replies
CreatePlease to create content