<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD:  ICMP Inspection Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3336630#M1065439</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;&lt;A id="link_14" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/372518" target="_self"&gt;ostorvacisco&lt;/A&gt;, let me modify your lines.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;no inspect&amp;nbsp;&lt;STRONG&gt;icmp&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;A id="link_9" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/263732" target="_self"&gt;hashimwajid1&lt;/A&gt;, also you can check inspect drop with:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show service-policy&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show asp drop&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;Regards.-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2018 13:13:27 GMT</pubDate>
    <dc:creator>#Mat</dc:creator>
    <dc:date>2018-02-23T13:13:27Z</dc:date>
    <item>
      <title>FTD:  ICMP Inspection Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3199518#M1065435</link>
      <description>&lt;P&gt;&amp;nbsp;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;recently i deployed FTD 2140 in HA. i created multiple sub-interfaces on FTD for inter-vlan routing. i am facing one issue regarding Ping between host in different VLANs and i am not able to ping between hosts in different VLANs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- ICMP inspection is enable via flexconfig ( i can see in running-config icmp inspection)&lt;/P&gt;
&lt;P&gt;2- i also allowed ICMP in policy&lt;/P&gt;
&lt;P&gt;3- all traffic is permitted in firewall&lt;/P&gt;
&lt;P&gt;4- i can do RDP to host in different VLANs but cannot ping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5- in Packet capture only echo request can be seen but no echo reply&lt;/P&gt;
&lt;P&gt;6- in FMC log i cannot see ICMP reply&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FMC version is 6.2.2 and FTD version is 6.2.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3199518#M1065435</guid>
      <dc:creator>hashimwajid1</dc:creator>
      <dc:date>2020-02-21T14:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD:  ICMP Inspection Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3336614#M1065437</link>
      <description>&lt;P&gt;I had the same isse.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disabling icmp inspect fixed me issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can disable it with flexconfig:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; no inspect ftp&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 12:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3336614#M1065437</guid>
      <dc:creator>ostorvacisco</dc:creator>
      <dc:date>2018-02-23T12:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTD:  ICMP Inspection Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3336630#M1065439</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;&lt;A id="link_14" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/372518" target="_self"&gt;ostorvacisco&lt;/A&gt;, let me modify your lines.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;no inspect&amp;nbsp;&lt;STRONG&gt;icmp&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;A id="link_9" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/263732" target="_self"&gt;hashimwajid1&lt;/A&gt;, also you can check inspect drop with:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show service-policy&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show asp drop&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;Regards.-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3336630#M1065439</guid>
      <dc:creator>#Mat</dc:creator>
      <dc:date>2018-02-23T13:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD:  ICMP Inspection Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3336736#M1065441</link>
      <description>&lt;P&gt;Thank you Matias.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To troubleshoot deeper you can capture packets, with the following capture you can see what packets are drop in ASP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;capture CAP type asp-drop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show capture CAP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2: 10:55:09.590957 802.1Q vlan#3604 P6 arp reply 192.168.236.85 is-at 0:0:c:9f:fe:14 Drop-reason: (l2_same-lan-port) L2 Src/Dst same LAN port&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I realized that some arp-reply&amp;nbsp;were discarded, I dont know exactly why, but disabling that inspect the issue disapeared.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Oscar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 15:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3336736#M1065441</guid>
      <dc:creator>ostorvacisco</dc:creator>
      <dc:date>2018-02-23T15:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD:  ICMP Inspection Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3351151#M1065443</link>
      <description>&lt;P&gt;Hi, today I had this issue I found that FTD&amp;nbsp;6.2 has ICMP&amp;nbsp;inspection disable by default.&lt;/P&gt;
&lt;P&gt;For enabling you can do it by CLI:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;configure inspection ICMP enable&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.-&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 19:59:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-icmp-inspection-issue/m-p/3351151#M1065443</guid>
      <dc:creator>#Mat</dc:creator>
      <dc:date>2018-03-19T19:59:36Z</dc:date>
    </item>
  </channel>
</rss>

