<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you post a picture of in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583161#M197909</link>
    <description>&lt;P&gt;Can you post a picture of your topology?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jan 2015 15:08:03 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2015-01-15T15:08:03Z</dc:date>
    <item>
      <title>Cisco ASA 5505 Denied ICMP type=0, no matching session</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583160#M197908</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I setup routing in my ASA to a lab environment (static routing from the ASA), I can from my Lab ping my cisco ASA, and from my Cisco ASA ping the Lab,&amp;nbsp;I can't ping from the lab to, for example my cisco switch connected behind the ASA (or anything else on my LAN), when I do this I get the following message in the ASA (172.16.30.2 is my Switch):&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(61, 61, 61); font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 14px; line-height: 17.5px;"&gt;Jan 14 2015 13:16:13: %ASA-4-313004: Denied ICMP type=0, from laddr 172.16.30.2 on interface inside to 172.16.1.10: no matching session&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know why I get this message, if it's because the ASA complains about some kind of asymmetric routing or some rule in the ASA that's blocking this, the thing is that in this case that's not really important :), just curious if you can permit this in some way?&lt;/P&gt;&lt;P&gt;The lab consists of Cisco routers.&lt;/P&gt;&lt;P&gt;Anyone know who to permit this in the ASA? Would be really helpful!!!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Image on ASA is:asa922-4-k8.bin)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for reading this!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:20:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583160#M197908</guid>
      <dc:creator>Johan Kardell</dc:creator>
      <dc:date>2019-03-12T05:20:55Z</dc:date>
    </item>
    <item>
      <title>Can you post a picture of</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583161#M197909</link>
      <description>&lt;P&gt;Can you post a picture of your topology?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2015 15:08:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583161#M197909</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2015-01-15T15:08:03Z</dc:date>
    </item>
    <item>
      <title>Sure!The Lab is on a computer</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583162#M197910</link>
      <description>&lt;P&gt;Sure!&lt;/P&gt;&lt;P&gt;The Lab&amp;nbsp;is on a computer running GNS3, this might be what the ASA don't like...?&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;A bit more explanation:&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;I have connected my GNS3 environment to my real network.&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;I have setup BGP and OSPF in GNS3 and static routes in my Cisco ASA to the GNS3 network&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;(in the ASA 172.16.1.0/24 and 192.168.1.0/24 to the interface on VMA-01R facing my real network, that's&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1" style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;route inside 172.16.1.0 255.255.255.0 172.16.30.13&lt;/P&gt;&lt;P class="p1" style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;route inside 192.168.1.0 255.255.255.0 172.16.30.13).&lt;/P&gt;&lt;P class="p1" style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;in RNK-02R I have a default route (that's coming via BGP from VMA-01R) to VMA-01R and in VMA-01R I have the connection to my real environment.&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;From the ASA I can successfully ping my GNS3 routers, and from GNS3 I can ping the Cisco ASA firewall, but when I try to ping anything else on my internal network the ASA complains with the following message:&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1" style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;Jan 14 2015 13:16:13: %ASA-4-313004: Denied ICMP type=0, from laddr 172.16.30.2 on interface inside to 172.16.1.10: no matching session&lt;/P&gt;&lt;P class="p1" style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1" style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; vertical-align: baseline; color: rgb(61, 61, 61); line-height: 21px;"&gt;(172.16.30.2 is in this case the CiscoSwitch, the CiscoSwitch and the Cisco ASA is on my real network).&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2015 15:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583162#M197910</guid>
      <dc:creator>Johan Kardell</dc:creator>
      <dc:date>2015-01-15T15:27:40Z</dc:date>
    </item>
    <item>
      <title>As a test can you put a</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583163#M197911</link>
      <description>&lt;P&gt;As a test can you put a static route in your switch?&lt;/P&gt;&lt;P&gt;ip route 172.16.1.10 255.255.255.255&amp;nbsp;172.16.30.13&lt;/P&gt;&lt;P&gt;Now try and ping 172.16.1.10&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2015 18:41:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583163#M197911</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2015-01-15T18:41:45Z</dc:date>
    </item>
    <item>
      <title>Thanks, but I can't :/, it's</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583164#M197912</link>
      <description>&lt;P&gt;Thanks, but I can't :/, it's a Cisco 2940.&lt;BR /&gt;Thinking about trying to replace the Cisco ASA with a Cisco Router, temporary, and see if this work, I can't do this until Saturday though (don't have the eq. right now), but I would prefer if it was possible to get the ASA to somehow permit this since the ASA is my "real" connection to the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Sorry, I accidentally clicked correct answer)&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2015 19:04:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583164#M197912</guid>
      <dc:creator>Johan Kardell</dc:creator>
      <dc:date>2015-01-15T19:04:37Z</dc:date>
    </item>
    <item>
      <title>Ah ok. ICMP on the ASA can be</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583165#M197913</link>
      <description>&lt;P&gt;Ah ok. ICMP on the ASA can be a PIA especially when traversing interfaces. A couple of other things to check. First do you have "same-security-traffic permit intra-interface" configured? In the logs on the ASA are you getting an error pertaining to IP Redirects or tcp state failure (you will have to try "telnet 172.16.1.10")&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2015 19:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583165#M197913</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2015-01-15T19:10:15Z</dc:date>
    </item>
    <item>
      <title>Ok, :), I enabled "same</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583166#M197914</link>
      <description>&lt;P&gt;Ok, :), I enabled "same-security-traffic.." on the ASA, no I can from my client ping the env. on the Lab, but can't do for ex. telnet.&lt;/P&gt;&lt;P&gt;I tried to telnet a loopback on the lab "192.168.1.6" from my client on the real Lan.&lt;/P&gt;&lt;P&gt;From the lab i still can't ping anything on 172.16.30.0/24 network, please see attachment from ASA log - thanks for all your help Collin!&lt;/P&gt;&lt;P&gt;Any ideas :/?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 11:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583166#M197914</guid>
      <dc:creator>Johan Kardell</dc:creator>
      <dc:date>2015-01-16T11:53:41Z</dc:date>
    </item>
    <item>
      <title>Okej! I got i to work :)!!!I</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583167#M197915</link>
      <description>&lt;P&gt;Okej! I got i to work :)!!!&lt;/P&gt;&lt;P&gt;I enabled "&lt;SPAN style="font-size: 14px;"&gt;same-security-traffic permit intra-interface" and&amp;nbsp;followed this guide, this guide&amp;nbsp;did the trick with the telnet as well!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"http://www.matthewjwhite.co.uk/2012/02/13/asymmetric-routing-with-cisco-asa-firewalls/"&lt;/P&gt;&lt;P&gt;Thanks for all the help! - This might not be the optimal solution, but in my case this is what I needed.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jan 2015 13:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-denied-icmp-type-0-no-matching-session/m-p/2583167#M197915</guid>
      <dc:creator>Johan Kardell</dc:creator>
      <dc:date>2015-01-17T13:39:20Z</dc:date>
    </item>
  </channel>
</rss>

