<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block ping to ASA but allow from certain IPs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122070#M1072149</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for a simple setup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Nobody should be able to ping my ASA's outside interface except (an Object group of) whitelisted IPs&lt;/P&gt;&lt;P&gt;2) We should be able to ping everything from inside to outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I achieve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 19:17:34 GMT</pubDate>
    <dc:creator>Brad_Shawh</dc:creator>
    <dc:date>2020-07-20T19:17:34Z</dc:date>
    <item>
      <title>Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122070#M1072149</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for a simple setup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Nobody should be able to ping my ASA's outside interface except (an Object group of) whitelisted IPs&lt;/P&gt;&lt;P&gt;2) We should be able to ping everything from inside to outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I achieve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 19:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122070#M1072149</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-07-20T19:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122073#M1072150</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;1. Use the command "&lt;EM&gt;&lt;STRONG&gt;icmp &lt;SPAN class="cCp_CmdPlain"&gt; {&lt;/SPAN&gt; permit &lt;SPAN class="cCp_CmdPlain"&gt; |&lt;/SPAN&gt; deny &lt;SPAN class="cCp_CmdPlain"&gt; }&lt;/SPAN&gt; ip_address net_mask &lt;SPAN class="cCp_CmdPlain"&gt; [&lt;/SPAN&gt; icmp_type &lt;SPAN class="cCp_CmdPlain"&gt; ]&lt;/SPAN&gt; if_name"&lt;/STRONG&gt;&lt;/EM&gt; to configure ICMP rules to ping the ASA's interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference:-&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/i1.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/i1.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Use command &lt;EM&gt;&lt;STRONG&gt;fixup protcol icmp&lt;/STRONG&gt;&lt;/EM&gt; to enable ICMP inspection for traffic through the ASA (from inside to outside).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 19:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122073#M1072150</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-07-20T19:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122074#M1072151</link>
      <description>&lt;P&gt;&lt;STRONG&gt;icmp permit any outside&amp;nbsp; - allow ping outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;then create an ACL to allow only those IP addresses.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 19:23:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122074#M1072151</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-07-20T19:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122075#M1072152</link>
      <description>&lt;P&gt;Could you please elaborate with an example? Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 19:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122075#M1072152</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-07-20T19:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122078#M1072153</link>
      <description>&lt;P class="pB1_Body1"&gt;The following example permits host 172.16.2.15 or hosts on subnet 172.22.1.0/16 to ping the outside interface:&lt;/P&gt;
&lt;PRE class="pB1_Body1"&gt;c&lt;SPAN&gt;iscoasa(config)# &lt;STRONG class="cBold"&gt;icmp permit host 172.16.2.15 echo-reply outside &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;c&lt;SPAN&gt;iscoasa(config)# &lt;STRONG class="cBold"&gt;icmp permit 172.22.1.0 255.255.0.0 echo-reply outside &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ciscoasa(config)# &lt;STRONG class="cBold"&gt;icmp permit any unreachable outside&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 19:31:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122078#M1072153</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-07-20T19:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122089#M1072154</link>
      <description>&lt;P&gt;# access-list ACL_IN permit icmp any any echo-reply&lt;BR /&gt;# access-list ACL_IN permit icmp any any echo&lt;BR /&gt;# access-list ACL_IN permit icmp any any time-exceeded &lt;BR /&gt;# access-group ACL_IN in interface outside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;create ACL_IN with the IP address in it.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 19:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4122089#M1072154</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-07-20T19:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123638#M1072227</link>
      <description>&lt;P&gt;Would access list work with 'to the box' traffic?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created the following ACL, please let me know if this is fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply outside&amp;nbsp; &amp;nbsp;&amp;lt;&amp;lt; ASA can ping any IP on Internet&lt;BR /&gt;icmp permit host a.b.c.d outside&amp;nbsp; &amp;lt;&amp;lt; a.b.c.d can ping ASA's Outside Interface&lt;BR /&gt;icmp deny any outside &amp;lt;&amp;lt; Nobody can ping ASA' Outside Interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*With this config, all my inside hosts are able to ping internet, which is fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 15:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123638#M1072227</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-07-22T15:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123647#M1072228</link>
      <description>&lt;P&gt;No. An access list assigned to an interface e.g. "access-list OUTSIDE_IN pemit|deny icmp any any" denies or pemits traffic &lt;STRONG&gt;through&lt;/STRONG&gt; the ASA not &lt;STRONG&gt;to&lt;/STRONG&gt; the ASA's interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The configuration you provided with the command starting &lt;STRONG&gt;icmp ....... &lt;/STRONG&gt;controls traffic &lt;STRONG&gt;to &lt;/STRONG&gt;the ASA's interface, and has nothing to do with allowing inside hosts to ping the internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 16:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123647#M1072228</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-07-22T16:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123668#M1072231</link>
      <description>&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please ignore my point about 'through the box' traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the configuration I pasted is good enough, correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two questions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) I assume there is no way to use object group in this 'icmp' acl? The best way to add entries is use ASDM and use 'insert' feature, correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) I tried using control plane ACL to deny ICMP traffic, it didn't work. Does control place ACL not work with ICMP?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 17:01:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123668#M1072231</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-07-22T17:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123670#M1072232</link>
      <description>No, unfortunately you cant use an object with the "icmp" acl.&lt;BR /&gt;&lt;BR /&gt;You would need to use the icmp command to control icmp traffic destinated to the ASA. A control plane ACL (rarely used IMO) could be used to control inbound VPN traffic (IPSec or SSL).</description>
      <pubDate>Wed, 22 Jul 2020 17:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123670#M1072232</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-07-22T17:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Block ping to ASA but allow from certain IPs</title>
      <link>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123678#M1072233</link>
      <description>&lt;P&gt;Thank you very much &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 17:25:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ping-to-asa-but-allow-from-certain-ips/m-p/4123678#M1072233</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-07-22T17:25:47Z</dc:date>
    </item>
  </channel>
</rss>

