<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Nothing special (access-list in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-ping/m-p/2455056#M267344</link>
    <description>&lt;P&gt;Nothing special (access-list or traffic inspection) is required to allow pings generated by the firewall itself.&lt;/P&gt;&lt;P&gt;If you want the firewall to respond to pings you need to allow that explicitly and turn on icmp inspection.&lt;/P&gt;&lt;P&gt;If you want to pass traceroute through and properly decrement the TTL so the firewall shows up in the trace you need to inspect icmp and make some other modifications as well.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2014 18:54:10 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-04-23T18:54:10Z</dc:date>
    <item>
      <title>Firewall Ping</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ping/m-p/2455055#M267343</link>
      <description>&lt;DIV class="blog-body" itemprop="text"&gt;&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;&lt;DIV class="field-items"&gt;&lt;DIV class="field-item even"&gt;&lt;P&gt;How do you allow your firewall to ping the internet ?&lt;/P&gt;&lt;P&gt;I have had the network working for over a year but when I try to ping from the firewall to the internet or anything for testing it just give me ?????. I am assuming it is a acl issue. I have access-list 101 extended permit icmp any any on the first line. That should allow the access correct?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ping/m-p/2455055#M267343</guid>
      <dc:creator>Joshua Maurer</dc:creator>
      <dc:date>2019-03-12T04:06:53Z</dc:date>
    </item>
    <item>
      <title>Nothing special (access-list</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ping/m-p/2455056#M267344</link>
      <description>&lt;P&gt;Nothing special (access-list or traffic inspection) is required to allow pings generated by the firewall itself.&lt;/P&gt;&lt;P&gt;If you want the firewall to respond to pings you need to allow that explicitly and turn on icmp inspection.&lt;/P&gt;&lt;P&gt;If you want to pass traceroute through and properly decrement the TTL so the firewall shows up in the trace you need to inspect icmp and make some other modifications as well.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 18:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ping/m-p/2455056#M267344</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-04-23T18:54:10Z</dc:date>
    </item>
    <item>
      <title>When you test what is the IP</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ping/m-p/2455057#M267346</link>
      <description>&lt;P&gt;When you test what is the IP that you are trying to ping? Also are you connected directly to your ISP on the public interface or is there any other device with the capability of blocking ICMP request or replies.&lt;/P&gt;&lt;P&gt;You can setup a capture on the external interface and if you see that the packet is captured most likely the block is outside your device.&lt;/P&gt;&lt;P&gt;EX capture interface outside match icmp host (public ip of the firewall) host 4.2.2.2&lt;/P&gt;&lt;P&gt;FYI icmp inspection is required for traffic that traverses the firewall. Since the traffic is started on the public interface to the internet this command is not required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2014 03:04:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ping/m-p/2455057#M267346</guid>
      <dc:creator>joseoroz</dc:creator>
      <dc:date>2014-04-24T03:04:07Z</dc:date>
    </item>
  </channel>
</rss>

