<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to edit fmc inspection policy for ping ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3750164#M1013083</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;You can enable disable inspection policy from cli.&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;gt; configure inspection icmp disable&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;You can also create flex config to disable inspections. Create flex config as below and bind to FTD&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;policy-map global_policy&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;class inspection_default&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp; no inspect icmp&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Abheesh&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Nov 2018 17:09:06 GMT</pubDate>
    <dc:creator>Abheesh Kumar</dc:creator>
    <dc:date>2018-11-20T17:09:06Z</dc:date>
    <item>
      <title>how to edit fmc inspection policy for ping ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3749908#M1013082</link>
      <description>&lt;P&gt;&lt;SPAN&gt;i have fmc with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Cisco Firepower 2110 ftd , i can browse the internet from inside fine but i cannot ping any outside ip address , i think it is denied in the inspection policy but i cant seem to find it in the fmc? where is the inspection policy in fmc?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3749908#M1013082</guid>
      <dc:creator>baselzind</dc:creator>
      <dc:date>2020-02-21T16:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to edit fmc inspection policy for ping ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3750164#M1013083</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;You can enable disable inspection policy from cli.&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;gt; configure inspection icmp disable&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;You can also create flex config to disable inspections. Create flex config as below and bind to FTD&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;policy-map global_policy&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;class inspection_default&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp; no inspect icmp&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Abheesh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 17:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3750164#M1013083</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-20T17:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to edit fmc inspection policy for ping ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3752632#M1013084</link>
      <description>is "&amp;gt; configure inspection icmp disable" done on ftd or fmc , and if on fmc how do i do it as it isnt accepting it , i think there is pre-commands to be able to insert it as im getting the input in this form "admin@firepower:~$"?</description>
      <pubDate>Mon, 26 Nov 2018 10:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3752632#M1013084</guid>
      <dc:creator>baselzind</dc:creator>
      <dc:date>2018-11-26T10:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to edit fmc inspection policy for ping ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3752657#M1013085</link>
      <description>&lt;P&gt;You need to do it on FTD not FMC.&lt;/P&gt;
&lt;P&gt;You can also create a rule in ACP to allow ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Abheesh&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 10:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3752657#M1013085</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-26T10:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: how to edit fmc inspection policy for ping ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3752670#M1013086</link>
      <description>&lt;P&gt;You need to "inspect icmp" for ping to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise the FTD doesn't keep track of the icmp flows and thus when the icmp echo reply&amp;nbsp;is received&amp;nbsp;it is not recognized as part of an existing flow and is dropped.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note if you want traceroute to work, even more configuration is required. Paul Stewart explains how here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://packetu.com/2018/08/12/traceroute-through-firepower-threat-defense/" target="_blank"&gt;https://packetu.com/2018/08/12/traceroute-through-firepower-threat-defense/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 11:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-edit-fmc-inspection-policy-for-ping/m-p/3752670#M1013086</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-11-26T11:19:49Z</dc:date>
    </item>
  </channel>
</rss>

