<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: not make sense ping result in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/not-make-sense-ping-result/m-p/4586156#M1088946</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;(config)# fixup protocol icmp &lt;/PRE&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-blogs/cisco-asa-and-icmp-inspection/ba-p/3773485" target="_blank"&gt;https://community.cisco.com/t5/security-blogs/cisco-asa-and-icmp-inspection/ba-p/3773485&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Octavian&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2022 05:17:20 GMT</pubDate>
    <dc:creator>Octavian Szolga</dc:creator>
    <dc:date>2022-04-05T05:17:20Z</dc:date>
    <item>
      <title>not make sense ping result</title>
      <link>https://community.cisco.com/t5/network-security/not-make-sense-ping-result/m-p/4585962#M1088945</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would you please help me for basic question?&lt;/P&gt;&lt;P&gt;from PC2 I can not ping to pc1 or pc3. confirm 3 PC had correct IP and gateway.&lt;/P&gt;&lt;P&gt;if I put a router in pc 1 and pc3 then enable icmp debug, icmp can receive and had been reply.&lt;/P&gt;&lt;P&gt;So the question is why icmp can not come back. It should able to come back as this is stateful firewall. Am I right?&lt;/P&gt;&lt;P&gt;If I create an acl to allow pc1 and pc3 inbound, pc2 can ping to pc1 and pc3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why PC1 can ping to g0/2? Wan interface allow ping by default?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoasa# show access-list&lt;BR /&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;alert-interval 300&lt;BR /&gt;ciscoasa# show run int&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.0.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;nameif dmz&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 198.51.100.100 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="QQ截图20220405113334.png" style="width: 688px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/148060iB5B72AC9EE056F45/image-size/large?v=v2&amp;amp;px=999" role="button" title="QQ截图20220405113334.png" alt="QQ截图20220405113334.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/115904-asa-config-dmz-00.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/115904-asa-config-dmz-00.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 04:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-make-sense-ping-result/m-p/4585962#M1088945</guid>
      <dc:creator>gdy1039</dc:creator>
      <dc:date>2022-04-05T04:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: not make sense ping result</title>
      <link>https://community.cisco.com/t5/network-security/not-make-sense-ping-result/m-p/4586156#M1088946</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;(config)# fixup protocol icmp &lt;/PRE&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-blogs/cisco-asa-and-icmp-inspection/ba-p/3773485" target="_blank"&gt;https://community.cisco.com/t5/security-blogs/cisco-asa-and-icmp-inspection/ba-p/3773485&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 05:17:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-make-sense-ping-result/m-p/4586156#M1088946</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2022-04-05T05:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: not make sense ping result</title>
      <link>https://community.cisco.com/t5/network-security/not-make-sense-ping-result/m-p/4586175#M1088947</link>
      <description>&lt;P&gt;Dear Octavian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your prompt reply warm my heart.&lt;/P&gt;&lt;P&gt;Very appreciate for your help. It save my time and make me improve.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 05:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-make-sense-ping-result/m-p/4586175#M1088947</guid>
      <dc:creator>gdy1039</dc:creator>
      <dc:date>2022-04-05T05:58:38Z</dc:date>
    </item>
  </channel>
</rss>

