<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No matching connection for ICMP error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/4042658#M1067538</link>
    <description>&lt;P&gt;We had the same problem and log messages.&amp;nbsp;&lt;BR /&gt;The solution in our scenario is to disable IPv6 on the ethernet adapter of the affected notebook. After that, DNS was successful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Just in case, some other have the same problem, this might be an alternative solution.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Mar 2020 09:51:03 GMT</pubDate>
    <dc:creator>Kevin_W</dc:creator>
    <dc:date>2020-03-09T09:51:03Z</dc:date>
    <item>
      <title>No matching connection for ICMP error</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537528#M235142</link>
      <description>&lt;P&gt;I'm seeing this on our cisco pix 515e firewall log quite often:&lt;/P&gt;&lt;P&gt;Sep &amp;nbsp;1 13:42:52 192.168.120.248 %PIX-4-313005: No matching connection for ICMP error message: icmp src guest:192.168.0.10 dst outside:8.8.8.8 (type 3, code 3) on guest interface. &amp;nbsp;Original IP payload: udp src 8.8.8.8/53 dst 192.168.0.10/52456.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the firewall we have this set:&amp;nbsp;&amp;nbsp;ip address 192.168.0.248 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list guest-out extended permit icmp 192.168.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list guest-out extended permit icmp 192.168.0.0 255.255.255.0 any echo&amp;nbsp;&lt;BR /&gt;access-list guest-out extended permit icmp 192.168.0.0 255.255.255.0 any echo-reply&amp;nbsp;&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any outside&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;&amp;nbsp; inspect icmp&amp;nbsp;&lt;/P&gt;&lt;P&gt;mtu guest 1500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on a layer 3 switch we have this set:&lt;/P&gt;&lt;P&gt;ip dhcp pool guest_wifi_pool&lt;BR /&gt;&amp;nbsp;network 192.168.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;default-router 192.168.0.248&amp;nbsp;&lt;BR /&gt;&amp;nbsp;dns-server 8.8.8.8 8.8.4.4&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;BR /&gt;&amp;nbsp;ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then we have unifi access points in this switch. so far the source ips in the error message seem to be iphones!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 01:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537528#M235142</guid>
      <dc:creator>parisvcisco</dc:creator>
      <dc:date>2019-03-13T01:07:07Z</dc:date>
    </item>
    <item>
      <title>Hi  parisvcisco It looks like</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537529#M235143</link>
      <description>&lt;P&gt;Hi&amp;nbsp; &lt;SPAN class="fullname" itemprop="author"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/parisvcisco" title="View user profile."&gt;parisvcisco&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;It looks like the device who have assigned &lt;/SPAN&gt;the IP 192.168.0.10 is trying to use the DNS server (53) of the IP 8.8.8.8&amp;nbsp; and the ASA captures the destination is unreachable&amp;nbsp; (Type 3 ) and the port requested is unreachable (code 3).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It might be an application on the device or that the ASA could be dropping the request for security reasons.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suggest you to place a capture&amp;nbsp; on the inside and verify this&amp;nbsp; a DNS request and see which application might be causing this behavior.&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Randy -&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2014 20:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537529#M235143</guid>
      <dc:creator>rvarelac</dc:creator>
      <dc:date>2014-09-01T20:46:13Z</dc:date>
    </item>
    <item>
      <title>Yes on the switch I have set</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537530#M235144</link>
      <description>&lt;P&gt;Yes on the switch I have set the DNS server to be 8.8.8.8 and 8.8.4.4 for that vlan. Do I need to do something on the firewall to allow this?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 03:39:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537530#M235144</guid>
      <dc:creator>parisvcisco</dc:creator>
      <dc:date>2014-09-02T03:39:43Z</dc:date>
    </item>
    <item>
      <title>Hi ,  And the DNS service</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537531#M235145</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the DNS service works fine ? &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the ASA is not able to reach the DNS sometimes , can you check if the ASA is dropping the service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest you to place an ASP capture,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example :&lt;/P&gt;&lt;P&gt;Capture drop interface inside type asp-drop all&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wait a couple of seconds or start manually the DNS service (request)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And check the capture : Show capture drop | incl 53&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check on the service policy if the DNS has the inspection enable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please rate helpful post !&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Randy -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 16:10:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537531#M235145</guid>
      <dc:creator>rvarelac</dc:creator>
      <dc:date>2014-09-02T16:10:17Z</dc:date>
    </item>
    <item>
      <title>I don't have type available..</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537532#M235146</link>
      <description>&lt;P&gt;I don't have type available......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# capture drop interface inside ? &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list &amp;nbsp; &amp;nbsp; &amp;nbsp;Capture packets that match access-list&lt;BR /&gt;&amp;nbsp; buffer &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Configure size of capture buffer, default is 512 KB&lt;BR /&gt;&amp;nbsp; circular-buffer &amp;nbsp;Overwrite buffer from beginning when full, default is&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;non-circular&lt;BR /&gt;&amp;nbsp; ethernet-type &amp;nbsp; &amp;nbsp;Capture Ethernet packets of a particular type, default is IP&lt;BR /&gt;&amp;nbsp; headers-only &amp;nbsp; &amp;nbsp; Capture only L2, L3 and L4 headers of packet without data in&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;them&lt;BR /&gt;&amp;nbsp; match &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Capture packets matching five-tuple&lt;BR /&gt;&amp;nbsp; packet-length &amp;nbsp; &amp;nbsp;Configure maximum length to save from each packet, default&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;is 68 bytes&lt;BR /&gt;&amp;nbsp; real-time &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Display captured packets in real-time. Warning: using this&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;option with a slow console connection may result in an&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;excessive amount of non-displayed packets due to performance&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;limitations.&lt;BR /&gt;&amp;nbsp; trace &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Trace the captured packets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fyi this is a cisco pix 515e so pretty old!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 07:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537532#M235146</guid>
      <dc:creator>parisvcisco</dc:creator>
      <dc:date>2014-09-03T07:56:29Z</dc:date>
    </item>
    <item>
      <title>I was able to run this</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537533#M235147</link>
      <description>&lt;P&gt;I was able to run this:&lt;/P&gt;&lt;P&gt;capture asp type asp-drop all&lt;/P&gt;&lt;P&gt;# show capture asp | inc 8.8.8.8 &amp;nbsp;&lt;BR /&gt;327: 09:00:10.672618 802.1Q vlan#2&amp;nbsp;P0 192.168.0.25 &amp;gt; 8.8.8.8: icmp: 192.168.0.25 udp port 52444 unreachable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have&amp;nbsp;&lt;SPAN style="font-size: 14px;"&gt;icmp permit any outside but would&amp;nbsp;icmp permit any guest work/help?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 08:30:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537533#M235147</guid>
      <dc:creator>parisvcisco</dc:creator>
      <dc:date>2014-09-03T08:30:53Z</dc:date>
    </item>
    <item>
      <title>Hi,Any reason why your IP</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537534#M235148</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Any reason why your IP phone initiates the traffic for 8.8.8.8 ? can you check on the settings of ip phone and make sure it is as per your requirement....&lt;/P&gt;&lt;P&gt;Type 3 – Destination Unreachable&lt;/P&gt;&lt;P&gt;Code 3 - Destination port unreachable&lt;/P&gt;&lt;P&gt;for dns to work..... you need to allow domain in access-list.&lt;/P&gt;&lt;P&gt;access-list guest-out extended permit udp 192.168.0.0 255.255.255.0 host 8.8.8.8 eq domain&lt;/P&gt;&lt;P&gt;access-list guest-out extended permit udp 192.168.0.0 255.255.255.0 host 8.8.4.4 eq domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also you need to allow the echo-reply for this on inbound acl (outside) interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any to 192.168.0.0 - echo-reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 12:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537534#M235148</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-09-03T12:03:00Z</dc:date>
    </item>
    <item>
      <title>not ip phones just iphones!so</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537535#M235149</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;not ip phones just iphones!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;so vlan 2 is for the guest wifi and I want them to use Google's dns servers for DNS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;so on the switch that's doing the routing I have set:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;ip dhcp pool guest_wifi_pool&lt;BR style="font-size: 14px;" /&gt;&amp;nbsp;network 192.168.0.0 255.255.255.0&lt;BR style="font-size: 14px;" /&gt;&amp;nbsp;default-router 192.168.0.248&amp;nbsp;&lt;BR style="font-size: 14px;" /&gt;&amp;nbsp;dns-server 8.8.8.8 8.8.4.4&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Do I still need to do the steps have you have posted?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 12:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537535#M235149</guid>
      <dc:creator>parisvcisco</dc:creator>
      <dc:date>2014-09-03T12:07:59Z</dc:date>
    </item>
    <item>
      <title>Hi, Yes.... on your guest</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537536#M235150</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes.... on your guest connected interface you need to allow dns (domain) udp - 53 from guest lan to 8.8.8.8 / 8.8.4.4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And if you want to allow icmp access to those dns servers for checking or testing then you need to allow echo on guest connected interface acl and echo-reply on outside interface acl...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 12:25:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537536#M235150</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-09-03T12:25:08Z</dc:date>
    </item>
    <item>
      <title> at the moment i have access</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537537#M235151</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;at the moment i have&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;access-group guest-out in interface guest&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;do i need to do&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;access-group guest-in in interface guest&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;then&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;access-group guest-in&amp;nbsp;any to 192.168.0.0 - echo-reply&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 12:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537537#M235151</guid>
      <dc:creator>parisvcisco</dc:creator>
      <dc:date>2014-09-03T12:49:18Z</dc:date>
    </item>
    <item>
      <title>nope.... Please send me your</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537538#M235152</link>
      <description>&lt;P&gt;nope....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please send me your configuration file.... hide out the sensitive information and send me to this post or to the private message... i will suggest you on that..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 13:09:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/2537538#M235152</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-09-03T13:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: No matching connection for ICMP error</title>
      <link>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/4042658#M1067538</link>
      <description>&lt;P&gt;We had the same problem and log messages.&amp;nbsp;&lt;BR /&gt;The solution in our scenario is to disable IPv6 on the ethernet adapter of the affected notebook. After that, DNS was successful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Just in case, some other have the same problem, this might be an alternative solution.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 09:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-matching-connection-for-icmp-error/m-p/4042658#M1067538</guid>
      <dc:creator>Kevin_W</dc:creator>
      <dc:date>2020-03-09T09:51:03Z</dc:date>
    </item>
  </channel>
</rss>

