<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic is ASA Stateless? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/is-asa-stateless/m-p/4293119#M1078543</link>
    <description>&lt;P&gt;I Have asa 5508 with firepower module. Trafik goes inside to outside, Pat is active, and when respond came back to firewall, firewall drops it. I added acl to outside interface in. It worked. Is ASA stateless or does firepower module block it ?&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 15:06:54 GMT</pubDate>
    <dc:creator>aehtibarov</dc:creator>
    <dc:date>2021-02-17T15:06:54Z</dc:date>
    <item>
      <title>is ASA Stateless?</title>
      <link>https://community.cisco.com/t5/network-security/is-asa-stateless/m-p/4293119#M1078543</link>
      <description>&lt;P&gt;I Have asa 5508 with firepower module. Trafik goes inside to outside, Pat is active, and when respond came back to firewall, firewall drops it. I added acl to outside interface in. It worked. Is ASA stateless or does firepower module block it ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 15:06:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-asa-stateless/m-p/4293119#M1078543</guid>
      <dc:creator>aehtibarov</dc:creator>
      <dc:date>2021-02-17T15:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: is ASA Stateless?</title>
      <link>https://community.cisco.com/t5/network-security/is-asa-stateless/m-p/4293157#M1078545</link>
      <description>&lt;P&gt;The ASA is a stateful firewall. Through configuration you can force a stateless operation, but this is typically not done.&lt;/P&gt;
&lt;P&gt;Without any more information it is hard to tell what dropped the traffic. But this is what my crystal ball says:&lt;/P&gt;
&lt;P&gt;You are testing with a PING. The statefully inspected protocols are only TCP and UDP, ICMP by default is not. The moment you test with "real" traffic it will work. For ICMP you can use the following command to make that also stageful:&lt;/P&gt;
&lt;PRE&gt;fixup protocol icmp&lt;/PRE&gt;</description>
      <pubDate>Wed, 17 Feb 2021 16:08:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-asa-stateless/m-p/4293157#M1078545</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2021-02-17T16:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: is ASA Stateless?</title>
      <link>https://community.cisco.com/t5/network-security/is-asa-stateless/m-p/4293444#M1078563</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;Thank you,. it was really helpfull. The actual problem was routing. The packet that coming back to outside once untranslate and shows route to outside)).&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;fixup protocol icmp &lt;BR /&gt;helped me to check ping result from other source&lt;/PRE&gt;</description>
      <pubDate>Thu, 18 Feb 2021 06:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-asa-stateless/m-p/4293444#M1078563</guid>
      <dc:creator>rafail.sharifov</dc:creator>
      <dc:date>2021-02-18T06:14:32Z</dc:date>
    </item>
  </channel>
</rss>

