02-12-2009 09:24 AM
Hi,
In the Cisco ASA 8.0 Command Reference it says that "show icmp" can be used to display the ICMP configuration, but it is not available (at least not on our 5540s):
ciscoasa# show icmp
^
ERROR: % Invalid input detected at '^' marker.
ciscoasa#
We are running version 8.0(4) and 8.0(4)23. I am logging in with an account that has privilege level 15.
Does anyone know if this is a known bug?
Best regards,
Harry
02-12-2009 09:52 AM
What about "show run icmp"
02-12-2009 09:57 AM
You may also try bellow syntax to include icmp acls if any.
show run | inc icmp
02-13-2009 12:52 AM
Hi,
I understand that I could use "show run icmp" or "show run | include icmp", but I was hoping that the command "show icmp" would give some information about the status of the icmp access lists.
For instance how many packets that hit the different imcp permits and denies. Today I only see the log entries for denied attempts, but it would be nice to see how many packets hit the filters.
Also, I think that either the command should be available or it should not be listed in the command reference...
Best regards,
Harry
02-13-2009 07:52 AM
For instance there is not such command on the device:
ciscoasa# show icmp
^
ERROR: % Invalid input detected at '^' marker.
ciscoasa# show i?
idb igmp interface ip
ipsec ipv6 isakmp
ciscoasa# show i
My guesses this docs where copied from the PIX 6.X docs and that is why it shows the command there, as you can see it shows it is a pre existing command.
About showing the hits on acls, the only way is with show access-list and defining a criteria like icmp, about the icmp configuration to the device and from the device your option is show run icmp
http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s3.html#wp1427048
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide