<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Deny ping on outside interface while allowing inside hosts to ping external hosts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586139#M203556</link>
    <description>&lt;P&gt;Been wresting with this one for a bit not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running IOS 9.2 on a ASA5505&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell me how I could accomplish this? I know how to&amp;nbsp;disable ping on the outside interface using icmp deny any outside but then when I try to ping an external ip the replies seem to never come back.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:07:01 GMT</pubDate>
    <dc:creator>scotteberl</dc:creator>
    <dc:date>2019-03-12T05:07:01Z</dc:date>
    <item>
      <title>Deny ping on outside interface while allowing inside hosts to ping external hosts</title>
      <link>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586139#M203556</link>
      <description>&lt;P&gt;Been wresting with this one for a bit not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running IOS 9.2 on a ASA5505&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell me how I could accomplish this? I know how to&amp;nbsp;disable ping on the outside interface using icmp deny any outside but then when I try to ping an external ip the replies seem to never come back.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586139#M203556</guid>
      <dc:creator>scotteberl</dc:creator>
      <dc:date>2019-03-12T05:07:01Z</dc:date>
    </item>
    <item>
      <title>Denying ICMP packets</title>
      <link>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586140#M203557</link>
      <description>&lt;P&gt;Denying ICMP packets wholesale isn't a practice I recommend, only because you're disabling essential control packets along with ping requests. Instead of turning it off with "icmp deny any outside", try putting something like "deny icmp any any echo" in the ACL for your outside interface. This will prevent external ping traffic, but allow other ICMP to pass... including replies to ping requests generated by internal devices.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 02:46:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586140#M203557</guid>
      <dc:creator>ghostinthenet</dc:creator>
      <dc:date>2014-11-21T02:46:26Z</dc:date>
    </item>
    <item>
      <title>Thanks for the reply Jody. I</title>
      <link>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586141#M203558</link>
      <description>&lt;P&gt;Thanks for the reply Jody. I ended up getting it working using the following configuration items:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply OUTSIDE&lt;BR /&gt;icmp deny any echo OUTSIDE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 03:44:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586141#M203558</guid>
      <dc:creator>scotteberl</dc:creator>
      <dc:date>2014-11-21T03:44:29Z</dc:date>
    </item>
    <item>
      <title>That will work, too.Also, it</title>
      <link>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586142#M203559</link>
      <description>&lt;P&gt;That will work, too.&lt;/P&gt;&lt;P&gt;Also, it's best to make sure you're permitting all of the other ICMP types other than echo&amp;nbsp;so that you don't lose control functions like path mtu discovery, network unreachable, traceroute, &amp;amp;c.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 05:56:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586142#M203559</guid>
      <dc:creator>ghostinthenet</dc:creator>
      <dc:date>2014-11-21T05:56:26Z</dc:date>
    </item>
    <item>
      <title>So you don't see allowing</title>
      <link>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586143#M203560</link>
      <description>&lt;P&gt;So you don't see allowing ping to the outside interface of the ASA as a security concern?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 21:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586143#M203560</guid>
      <dc:creator>scotteberl</dc:creator>
      <dc:date>2014-11-21T21:34:50Z</dc:date>
    </item>
    <item>
      <title>Personally, no... but that's</title>
      <link>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586144#M203561</link>
      <description>&lt;P&gt;Personally, no... but that's up to you.&lt;/P&gt;&lt;P&gt;What I'm saying is that even if you&amp;nbsp;&lt;EM&gt;are&lt;/EM&gt;&amp;nbsp;blocking pings to your ASA, you should make sure that &lt;EM&gt;other&lt;/EM&gt; ICMP traffic is permitted in. These are used for various Internet control functions and you're potentially limiting functionality and troubleshooting capabilities by blocking them.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 22:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ping-on-outside-interface-while-allowing-inside-hosts-to/m-p/2586144#M203561</guid>
      <dc:creator>ghostinthenet</dc:creator>
      <dc:date>2014-11-21T22:28:08Z</dc:date>
    </item>
  </channel>
</rss>

