<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5506 Access Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4894993#M1103054</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/460403"&gt;@bwn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you can keep the same security level, use the command&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;EM&gt;same&lt;/EM&gt;-&lt;EM&gt;security&lt;/EM&gt;-&lt;EM&gt;traffic permit inter&lt;/EM&gt;-&lt;EM&gt;interface&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FlavioMiranda_0-1690559037906.png" style="width: 798px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192928i05A9DB72905BE780/image-dimensions/798x596?v=v2" width="798" height="596" role="button" title="FlavioMiranda_0-1690559037906.png" alt="FlavioMiranda_0-1690559037906.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2023 15:44:11 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2023-07-28T15:44:11Z</dc:date>
    <item>
      <title>ASA5506 Access Question</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4894989#M1103053</link>
      <description>&lt;P&gt;We have an ASA5506 and I'm trying to have an IP address that is accessible on the outside interface be accessible on the inside interface. I can ping the address if I select outside interface but there is no response when trying to ping from the inside interface. I'm using the ASDM tool as I don't spend a lot of time managing routers. I tried changing the security level of the outside interface to 100 to match the inside interface as I thought traffic may be allowed if the same security level but that didn't seem to make a difference.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 15:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4894989#M1103053</guid>
      <dc:creator>bwn</dc:creator>
      <dc:date>2023-07-28T15:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 Access Question</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4894993#M1103054</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/460403"&gt;@bwn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you can keep the same security level, use the command&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;EM&gt;same&lt;/EM&gt;-&lt;EM&gt;security&lt;/EM&gt;-&lt;EM&gt;traffic permit inter&lt;/EM&gt;-&lt;EM&gt;interface&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FlavioMiranda_0-1690559037906.png" style="width: 798px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192928i05A9DB72905BE780/image-dimensions/798x596?v=v2" width="798" height="596" role="button" title="FlavioMiranda_0-1690559037906.png" alt="FlavioMiranda_0-1690559037906.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 15:44:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4894993#M1103054</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-07-28T15:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 Access Question</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4894998#M1103055</link>
      <description>&lt;P&gt;1- icmp inspection&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2-allow icmp via inside acl if found&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3- route OUT 0.0.0.0 0.0.0.0 must add to asa&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 15:45:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4894998#M1103055</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-28T15:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 Access Question</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4895005#M1103056</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-07-28_11-54-01.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192929iBA4C21AA17173AA2/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-07-28_11-54-01.jpg" alt="2023-07-28_11-54-01.jpg" /&gt;&lt;/span&gt;I have done that as you can see in the screenshot attached. I've also set the security level the same. If I do a tracert from the outside interface it works fine but when I change to the inside_1 interface it hangs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 15:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4895005#M1103056</guid>
      <dc:creator>bwn</dc:creator>
      <dc:date>2023-07-28T15:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 Access Question</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4895042#M1103057</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/460403"&gt;@bwn&lt;/a&gt; for ICMP you either need to explictly permit ICMP echo-reply inbound on the outside interface ACL or as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt; mentioned enable ICMP inspection. Enable ICMP inspection using the CLI command &lt;STRONG&gt;fixup protocol icmp&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To allow traceroute from inside to outside then you need to permit icmp time-exceeded and unreachable inbound on the outsisde interface ACL. Example &lt;A href="https://integratingit.wordpress.com/2018/12/15/allow-icmp-traceroute-through-cisco-asa/" target="_blank"&gt;https://integratingit.wordpress.com/2018/12/15/allow-icmp-traceroute-through-cisco-asa/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also change the security level of the outside interface to 0, traffic from a low security level to a high level is denied as default (which is what you want on the outside interface).&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 17:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4895042#M1103057</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-07-28T17:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 Access Question</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4895150#M1103059</link>
      <description>&lt;P&gt;I've changed the outside security back to 0. Is this where I should be permitting the ICMP echo reply? Is there anywhere I need to add anything?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-07-28_16-32-59.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192957i33C75D846895C1FA/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-07-28_16-32-59.jpg" alt="2023-07-28_16-32-59.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 20:35:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4895150#M1103059</guid>
      <dc:creator>bwn</dc:creator>
      <dc:date>2023-07-28T20:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 Access Question</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4895155#M1103061</link>
      <description>&lt;PRE&gt;asa# packet-tracer input inside icmp x.x.x.x 8 0 y.y.y.y detail
&lt;/PRE&gt;
&lt;P&gt;x.x.x.x is inside subnet&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 21:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-access-question/m-p/4895155#M1103061</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-28T21:04:42Z</dc:date>
    </item>
  </channel>
</rss>

