<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking icmp through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocking-icmp-through-asa/m-p/2678544#M190456</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;config t&lt;BR /&gt;(config)# policy-map global_policy&lt;BR /&gt;(config-pmap)# class inspection_default&lt;BR /&gt;(config-pmap-c)# no inspect icmp&lt;BR /&gt;(config-pmap-c)# exit&lt;BR /&gt;(config-pmap)# exit&lt;BR /&gt;(config)# ping &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 216.58.196.100, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 80/84/90 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA gives logs in ASDM as follows:&lt;/P&gt;&lt;P&gt;An ICMP session was established in the fast-path when stateful ICMP was enabled using the &lt;FONT color="Black"&gt;&lt;B&gt;inspect icmp &lt;/B&gt;&lt;/FONT&gt;command. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have applied ACL &amp;nbsp;to block&amp;nbsp;any any ip and any any icmp&amp;nbsp;&amp;nbsp; on outside interface. Is this a normal behaviour of ASA. How do I block icmp ?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:08:42 GMT</pubDate>
    <dc:creator>shoaib sheikh</dc:creator>
    <dc:date>2019-03-12T06:08:42Z</dc:date>
    <item>
      <title>Blocking icmp through ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-icmp-through-asa/m-p/2678544#M190456</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;config t&lt;BR /&gt;(config)# policy-map global_policy&lt;BR /&gt;(config-pmap)# class inspection_default&lt;BR /&gt;(config-pmap-c)# no inspect icmp&lt;BR /&gt;(config-pmap-c)# exit&lt;BR /&gt;(config-pmap)# exit&lt;BR /&gt;(config)# ping &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 216.58.196.100, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 80/84/90 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA gives logs in ASDM as follows:&lt;/P&gt;&lt;P&gt;An ICMP session was established in the fast-path when stateful ICMP was enabled using the &lt;FONT color="Black"&gt;&lt;B&gt;inspect icmp &lt;/B&gt;&lt;/FONT&gt;command. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have applied ACL &amp;nbsp;to block&amp;nbsp;any any ip and any any icmp&amp;nbsp;&amp;nbsp; on outside interface. Is this a normal behaviour of ASA. How do I block icmp ?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-icmp-through-asa/m-p/2678544#M190456</guid>
      <dc:creator>shoaib sheikh</dc:creator>
      <dc:date>2019-03-12T06:08:42Z</dc:date>
    </item>
    <item>
      <title>Hi,Normal ACL would only</title>
      <link>https://community.cisco.com/t5/network-security/blocking-icmp-through-asa/m-p/2678545#M190461</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Normal ACL would only block traffic which is through the box.&lt;/P&gt;&lt;P&gt;This ping is initiated from the ASA device interface so you would need to use the "ICMP deny" command.&lt;/P&gt;&lt;P&gt;Refer:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/i1.html#pgfId-1779047&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 08:01:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-icmp-through-asa/m-p/2678545#M190461</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-18T08:01:20Z</dc:date>
    </item>
    <item>
      <title>Thanks Vibhor .</title>
      <link>https://community.cisco.com/t5/network-security/blocking-icmp-through-asa/m-p/2678546#M190466</link>
      <description>&lt;P&gt;Thanks Vibhor .&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2015 03:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-icmp-through-asa/m-p/2678546#M190466</guid>
      <dc:creator>shoaib sheikh</dc:creator>
      <dc:date>2015-06-22T03:57:42Z</dc:date>
    </item>
  </channel>
</rss>

