<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CBAC ICMP inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-icmp-inspection/m-p/2438060#M267376</link>
    <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;Can any one tell me whether CBAC can inspect the ICMP traffic or not.&lt;/P&gt;&lt;P&gt;According to CISCO configuration guide it cannot inspect non IP traffic following is mentioned in the cisco configuration guide (&lt;STRONG&gt;Data Plane Configuration Guide Context-Based Access Control Firewall&lt;/STRONG&gt; ) for CBAC .&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Supports only TCP and UDP IP protocol traffic. Other IP traffic, such as Internet Control Message Protocol (ICMP), is not inspected by CBAC and should be filtered with basic access lists&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;But following command allow the ICMP inspection.&lt;/P&gt;&lt;P&gt;When i ping from my window machine attached to cloud R2 and R3 reply the ping packet:-&lt;/P&gt;&lt;P&gt;R1(config)#access-list 101 deny ip any any&lt;/P&gt;&lt;P&gt;R1(config)#ip inspect name CBAC icmp&lt;/P&gt;&lt;P&gt;R1(config)#interface FastEthernet0/0&lt;BR /&gt;R1(config-if)# ip inspect CBAC out&lt;BR /&gt;R1(config-if)# ip access-group 101 in&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:06:23 GMT</pubDate>
    <dc:creator>pankaj kumar</dc:creator>
    <dc:date>2019-03-12T04:06:23Z</dc:date>
    <item>
      <title>CBAC ICMP inspection</title>
      <link>https://community.cisco.com/t5/network-security/cbac-icmp-inspection/m-p/2438060#M267376</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;Can any one tell me whether CBAC can inspect the ICMP traffic or not.&lt;/P&gt;&lt;P&gt;According to CISCO configuration guide it cannot inspect non IP traffic following is mentioned in the cisco configuration guide (&lt;STRONG&gt;Data Plane Configuration Guide Context-Based Access Control Firewall&lt;/STRONG&gt; ) for CBAC .&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Supports only TCP and UDP IP protocol traffic. Other IP traffic, such as Internet Control Message Protocol (ICMP), is not inspected by CBAC and should be filtered with basic access lists&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;But following command allow the ICMP inspection.&lt;/P&gt;&lt;P&gt;When i ping from my window machine attached to cloud R2 and R3 reply the ping packet:-&lt;/P&gt;&lt;P&gt;R1(config)#access-list 101 deny ip any any&lt;/P&gt;&lt;P&gt;R1(config)#ip inspect name CBAC icmp&lt;/P&gt;&lt;P&gt;R1(config)#interface FastEthernet0/0&lt;BR /&gt;R1(config-if)# ip inspect CBAC out&lt;BR /&gt;R1(config-if)# ip access-group 101 in&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-icmp-inspection/m-p/2438060#M267376</guid>
      <dc:creator>pankaj kumar</dc:creator>
      <dc:date>2019-03-12T04:06:23Z</dc:date>
    </item>
    <item>
      <title>Stateful inspection of ICMP</title>
      <link>https://community.cisco.com/t5/network-security/cbac-icmp-inspection/m-p/2438061#M267379</link>
      <description>&lt;P&gt;Stateful inspection of ICMP packets is limited to the most common types of ICMP messages that are useful to network administrators who are trying to debug their networks. That is, ICMP messages that do not provide a valuable tool for the internal network administrator will not be allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;ICMP Packet Types Supported by CBAC:&lt;/P&gt;&lt;P&gt;Echo Reply,Destination Unreachable,Echo Request,Time Exceeded,Timestamp Request,Timestamp Reply&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer &lt;A href="http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_protocol_cbac_fw/configuration/15-2mt/sec-prot-cbac-fw-15-2mt-book/sec-prot-fw-state-icmp.html"&gt;this document&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;"Please rate helpful posts"&lt;/P&gt;</description>
      <pubDate>Sun, 20 Apr 2014 11:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-icmp-inspection/m-p/2438061#M267379</guid>
      <dc:creator>Poonam Garg</dc:creator>
      <dc:date>2014-04-20T11:56:22Z</dc:date>
    </item>
  </channel>
</rss>

