<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic An acl is used to control in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466226#M267309</link>
    <description>&lt;P&gt;An acl is used to control traffic through the firewall and not to interfaces on the firewall itself. That is why you do not see any hits when you ping the outside inteface.&lt;/P&gt;&lt;P&gt;The ASA by default allows all ICMP to any interface unless you configure it otherwise so that is why even without an acl it is still allowed.&lt;/P&gt;&lt;P&gt;See this link for details on how to configure the ASA in terms of controlling ICMP to the firewall interfaces -&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/i1.html#pgfId-1779047&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
    <pubDate>Fri, 25 Apr 2014 13:39:20 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2014-04-25T13:39:20Z</dc:date>
    <item>
      <title>ACL on Outside Interface not being hit</title>
      <link>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466225#M267306</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;on my ASA Outside Interface I have the following configured -&lt;/P&gt;&lt;P&gt;access-list out_in extended permit icmp any any alternate-address&lt;BR /&gt;access-list out_in extended permit icmp any any echo&lt;BR /&gt;access-list out_in extended permit icmp any any traceroute&lt;BR /&gt;access-list out_in extended permit icmp any any time-exceeded&lt;BR /&gt;access-list out_in extended permit icmp any any unreachable&lt;BR /&gt;access-list out_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-group out_in in interface outside&lt;/P&gt;&lt;P&gt;When pinging my IP address of the Outside Int - and then checking my ACL, I see no hits against it. Have I gone wrong somewhere? Also, even when I remove the ACL I can still ping the Interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:07:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466225#M267306</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2019-03-12T04:07:18Z</dc:date>
    </item>
    <item>
      <title>An acl is used to control</title>
      <link>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466226#M267309</link>
      <description>&lt;P&gt;An acl is used to control traffic through the firewall and not to interfaces on the firewall itself. That is why you do not see any hits when you ping the outside inteface.&lt;/P&gt;&lt;P&gt;The ASA by default allows all ICMP to any interface unless you configure it otherwise so that is why even without an acl it is still allowed.&lt;/P&gt;&lt;P&gt;See this link for details on how to configure the ASA in terms of controlling ICMP to the firewall interfaces -&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/i1.html#pgfId-1779047&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 13:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466226#M267309</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-04-25T13:39:20Z</dc:date>
    </item>
    <item>
      <title>Thanks for that Jon.If I</title>
      <link>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466227#M267311</link>
      <description>&lt;P&gt;Thanks for that Jon.&lt;/P&gt;&lt;P&gt;If I wanted to then control ICMP to the interface would I just use this global command&lt;/P&gt;&lt;P&gt;&lt;B class="cCN_CmdName" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;icmp&amp;nbsp;&lt;/B&gt;&lt;SPAN class="cCp_CmdPlain" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;{&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;B class="cCN_CmdName" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;permit&lt;/B&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;|&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;B class="cCN_CmdName" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;deny&lt;/B&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;}&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;I&gt;any&lt;/I&gt;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;[&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cCi_CmdItalic" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;icmp_type&lt;/EM&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;]&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; line-height: normal;"&gt;&amp;nbsp;&lt;I&gt;outside&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This is assuming the any option is available. Not at my ASA just now to check.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 16:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466227#M267311</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2014-04-25T16:19:22Z</dc:date>
    </item>
    <item>
      <title>If I wanted to then control</title>
      <link>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466228#M267312</link>
      <description>&lt;P&gt;&lt;EM&gt;If I wanted to then control ICMP to the interface would I just use this global command&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;icmp&amp;nbsp;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;{&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;&lt;/SPAN&gt;permit&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;|&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;&lt;/SPAN&gt;deny&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;}&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;any&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;[&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;&lt;/SPAN&gt;icmp_type&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;]&lt;/SPAN&gt;&lt;SPAN style="color:rgb(0, 0, 0); font-family:Arial, Helvetica, sans-serif; line-height:normal"&gt;&amp;nbsp;outside&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Yes you would.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 19:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-on-outside-interface-not-being-hit/m-p/2466228#M267312</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-04-25T19:20:16Z</dc:date>
    </item>
  </channel>
</rss>

