<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5540 dropping packets in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5540-dropping-packets/m-p/2767915#M177705</link>
    <description>&lt;P&gt;I have an ASA 5540 that is behaving strangely.&amp;nbsp; I have two interfaces, both at the same security level - 0.&amp;nbsp; In the Access Rules there are only two - the implicit deny all and before that I created a simple one to allow all (source:any, destination:any, service:ip &amp;amp; icmp, permit).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try to ping across it it doesn't work.&amp;nbsp; Using the Packet Tracer in ADSM it tells me that an implicit rule is dropping an icmp packet from my source to my destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&amp;nbsp; I'm stumped by this!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:45:12 GMT</pubDate>
    <dc:creator>Brian Green</dc:creator>
    <dc:date>2019-03-12T06:45:12Z</dc:date>
    <item>
      <title>ASA 5540 dropping packets</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-dropping-packets/m-p/2767915#M177705</link>
      <description>&lt;P&gt;I have an ASA 5540 that is behaving strangely.&amp;nbsp; I have two interfaces, both at the same security level - 0.&amp;nbsp; In the Access Rules there are only two - the implicit deny all and before that I created a simple one to allow all (source:any, destination:any, service:ip &amp;amp; icmp, permit).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try to ping across it it doesn't work.&amp;nbsp; Using the Packet Tracer in ADSM it tells me that an implicit rule is dropping an icmp packet from my source to my destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&amp;nbsp; I'm stumped by this!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-dropping-packets/m-p/2767915#M177705</guid>
      <dc:creator>Brian Green</dc:creator>
      <dc:date>2019-03-12T06:45:12Z</dc:date>
    </item>
    <item>
      <title>Hi,By default traffic between</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-dropping-packets/m-p/2767916#M177706</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;By default traffic between interfaces with same security level is not allowed.&lt;/P&gt;&lt;P&gt;Try the command :&amp;nbsp;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!!!&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;Mark the answer as correct if it helps in resolving your query!!!&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 14:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-dropping-packets/m-p/2767916#M177706</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-15T14:24:26Z</dc:date>
    </item>
    <item>
      <title>I tried adding that - it didn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-dropping-packets/m-p/2767917#M177707</link>
      <description>&lt;P&gt;I tried adding that - it didn't seem to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One other thing I notice - on the device, when I ping an address in the range of the external interface (i.e. not on the other side of a router) I get a ? telling me that it doesn't know how to get there, even though it is inside the same subnet.&amp;nbsp; Is it possible that this firewall is dead?&amp;nbsp; Or should I try another interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 15:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-dropping-packets/m-p/2767917#M177707</guid>
      <dc:creator>Brian Green</dc:creator>
      <dc:date>2015-10-15T15:42:32Z</dc:date>
    </item>
  </channel>
</rss>

