<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ping through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995467#M434584</link>
    <description>&lt;P&gt;Could some security expert please help me understand icmp behavior for an ASA running 8.0 or 8.2? &lt;/P&gt;&lt;P&gt;My inside hosts (sitting behind the inside interface of ASA) can ping an external IP (on internet) . But when I ping that same external IP from the firewall, I don't get any reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kashish&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:16:52 GMT</pubDate>
    <dc:creator>Kashish_Patel</dc:creator>
    <dc:date>2019-03-11T23:16:52Z</dc:date>
    <item>
      <title>ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995467#M434584</link>
      <description>&lt;P&gt;Could some security expert please help me understand icmp behavior for an ASA running 8.0 or 8.2? &lt;/P&gt;&lt;P&gt;My inside hosts (sitting behind the inside interface of ASA) can ping an external IP (on internet) . But when I ping that same external IP from the firewall, I don't get any reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kashish&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995467#M434584</guid>
      <dc:creator>Kashish_Patel</dc:creator>
      <dc:date>2019-03-11T23:16:52Z</dc:date>
    </item>
    <item>
      <title>ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995468#M434585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have "icmp" command configured on your ASA that might be blocking it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure:&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 02:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995468#M434585</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-08T02:18:56Z</dc:date>
    </item>
    <item>
      <title>ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995469#M434586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per packet tracer, ping should be successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group citrix-dmz1-perm-all-tmp in interface citrix-dmz1&lt;/P&gt;&lt;P&gt;access-list citrix-dmz1-perm-all-tmp extended permit ip any any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 1746235146, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: output and adjacency&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;found next-hop 10.244.16.185 using egress ifc outside&lt;/P&gt;&lt;P&gt;adjacency Active&lt;/P&gt;&lt;P&gt;next-hop mac address 0015.63e8.d3d1 hits 12697093&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: citrix-dmz1&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still only the inside hosts (sitting behind the inside interface of ASA) can ping an&amp;nbsp; external IP (on internet) . But when I ping that same external IP from&amp;nbsp; the firewall, I don't get any reply.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 02:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995469#M434586</guid>
      <dc:creator>Kashish_Patel</dc:creator>
      <dc:date>2012-06-08T02:48:44Z</dc:date>
    </item>
    <item>
      <title>ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995470#M434587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please share your config. Thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 02:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995470#M434587</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-08T02:49:50Z</dc:date>
    </item>
    <item>
      <title>ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995471#M434588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have sent you the config file as a private message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ritika&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 03:02:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995471#M434588</guid>
      <dc:creator>Kashish_Patel</dc:creator>
      <dc:date>2012-06-08T03:02:53Z</dc:date>
    </item>
    <item>
      <title>ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995472#M434589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason why you can't ping from the ASA itself is because your ASA outside interface has private IP Address hence it's not routable on the Internet.&lt;/P&gt;&lt;P&gt;All your internal network has public IP assigned, therefore you can ping external host on the Internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 03:05:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-through-asa/m-p/1995472#M434589</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-08T03:05:02Z</dc:date>
    </item>
  </channel>
</rss>

