<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic packet tracer showing drop in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057893#M402615</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I tried packet tracer as you updated : &lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 172.25.28.23 8 0 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you tell me what does icmp type 8 mean and icmp code 0 mean?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Oct 2012 07:12:59 GMT</pubDate>
    <dc:creator>Kashish_Patel</dc:creator>
    <dc:date>2012-10-17T07:12:59Z</dc:date>
    <item>
      <title>packet tracer showing drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057889#M402607</link>
      <description>&lt;P&gt;My firewall is running on 8.2(5)33 version. I am facing a problem where config looks fine, but still firewall is dropping packet (I saw this in packet tracer).&lt;/P&gt;&lt;P&gt;I am pasting packet tracer output below. In the final result, it says acl-drop, but ACL is allowing icmps as shown in phase 2. What am I missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw1# packet-tracer input inside icmp 172.25.28.23 2 3 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group to-outside in interface inside&lt;/P&gt;&lt;P&gt;access-list to-outside extended permit icmp any any &lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (inside) 2 access-list nat-to-fixed-global-ip&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside host 172.25.28.23 outside host 1.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 2 (&amp;lt;nat IP&amp;gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 4, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057889#M402607</guid>
      <dc:creator>Kashish_Patel</dc:creator>
      <dc:date>2019-03-12T00:10:29Z</dc:date>
    </item>
    <item>
      <title>packet tracer showing drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057890#M402609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's dropping due to NAT on Phase 5 of your packet tracer output.&lt;/P&gt;&lt;P&gt;Check the NAT statement to see if it has been correctly configured, and if you just configure a new translation statement, make sure that you have "clear xlate".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 05:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057890#M402609</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-17T05:32:02Z</dc:date>
    </item>
    <item>
      <title>packet tracer showing drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057891#M402611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for replying. I did "clear xlate". Still packet tracer is showing drop. Nat statement is correctly configured. If you want to check, I can share the config offline.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 06:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057891#M402611</guid>
      <dc:creator>Kashish_Patel</dc:creator>
      <dc:date>2012-10-17T06:01:39Z</dc:date>
    </item>
    <item>
      <title>packet tracer showing drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057892#M402612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are you trying to test with packet tracer?&lt;/P&gt;&lt;P&gt;Ping? if it is, then it should have been:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 172.25.28.23 8 0 1.1.1.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 06:57:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057892#M402612</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-17T06:57:52Z</dc:date>
    </item>
    <item>
      <title>packet tracer showing drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057893#M402615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I tried packet tracer as you updated : &lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 172.25.28.23 8 0 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you tell me what does icmp type 8 mean and icmp code 0 mean?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 07:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057893#M402615</guid>
      <dc:creator>Kashish_Patel</dc:creator>
      <dc:date>2012-10-17T07:12:59Z</dc:date>
    </item>
    <item>
      <title>packet tracer showing drop</title>
      <link>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057894#M402616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.nthelp.com/icmp.html"&gt;http://www.nthelp.com/icmp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 07:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-tracer-showing-drop/m-p/2057894#M402616</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2012-10-17T07:22:30Z</dc:date>
    </item>
  </channel>
</rss>

