<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: asa 7.0.2 and access-list element removing not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454664#M429699</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's true, now how to remove timeout icmp 0:00:02 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"no timeout icmp" and "timeout 0:00:00" does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Sep 2005 06:09:28 GMT</pubDate>
    <dc:creator>r.spiandorello</dc:creator>
    <dc:date>2005-09-05T06:09:28Z</dc:date>
    <item>
      <title>asa 7.0.2 and access-list element removing not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454660#M429690</link>
      <description>&lt;P&gt;Hy,asa 5510 with 7.0.2 version and icmp echo traffic from dmz host to an outside host and echo-reply from the outside host to dmz host.&lt;/P&gt;&lt;P&gt;If I remove the specific ace of the icmp, the traffic still goes-on even if it remains only the ace "deny ip any any" on the 2 access-lists.&lt;/P&gt;&lt;P&gt;With show conn I can see the 2 icmp sessions.&lt;/P&gt;&lt;P&gt;Why ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454660#M429690</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2020-02-21T08:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: asa 7.0.2 and access-list element removing not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454661#M429693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i think the reason is due to the fact that icmp fixup is enabled, allowing echo replies to come back&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2005 21:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454661#M429693</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-09-02T21:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: asa 7.0.2 and access-list element removing not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454662#M429696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hy, thank you but it runs even if I remove the access-list element that allows the echo.&lt;/P&gt;&lt;P&gt;Could it be related to the new icmp timeout parameter ?&lt;/P&gt;&lt;P&gt;After I have removed the access-list element, if I stop the pc to ping and then I start it again, the new ping is denied.&lt;/P&gt;&lt;P&gt;It seems like the "icmp session" within the timeout is allowed.&lt;/P&gt;&lt;P&gt;Greatings&lt;/P&gt;&lt;P&gt;Renato&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Sep 2005 11:53:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454662#M429696</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2005-09-03T11:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: asa 7.0.2 and access-list element removing not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454663#M429698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so for the existing ICMP sessions, they are letting through, but the new sessions will not be.&lt;/P&gt;&lt;P&gt;if you remove the ACL, then do a clear xlat, it will brake your contiuous icmp as well&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Sep 2005 18:02:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454663#M429698</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-09-03T18:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: asa 7.0.2 and access-list element removing not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454664#M429699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's true, now how to remove timeout icmp 0:00:02 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"no timeout icmp" and "timeout 0:00:00" does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2005 06:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-7-0-2-and-access-list-element-removing-not-working/m-p/454664#M429699</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2005-09-05T06:09:28Z</dc:date>
    </item>
  </channel>
</rss>

