<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ping allowed but not configured in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907029#M457324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roman,&lt;/P&gt;&lt;P&gt;I appreciate the reply but neither of those commands are configured on the ASA and there are no inspect statements allowing icmp and only the implicit deny access rule is configured on the outside interface so I'm still confused as to what is allowing the pings to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Apr 2012 19:50:34 GMT</pubDate>
    <dc:creator>jeff6strings</dc:creator>
    <dc:date>2012-04-05T19:50:34Z</dc:date>
    <item>
      <title>Ping allowed but not configured</title>
      <link>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907027#M457322</link>
      <description>&lt;P&gt;We have a Cisco ASA 5580 and the outside interface has a public IP address and we noticed we can ping this address from the Internet. I did a packet capture on the outside interface and confirmed the pings and the IP address sending the pings. The 5580 does not have an access list allowing icmp so I'm not sure what is allowing the pings to this interface.&lt;/P&gt;&lt;P&gt;Appreciate any help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907027#M457322</guid>
      <dc:creator>jeff6strings</dc:creator>
      <dc:date>2019-03-11T22:51:09Z</dc:date>
    </item>
    <item>
      <title>Ping allowed but not configured</title>
      <link>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907028#M457323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any unreachable outside&lt;/P&gt;&lt;P&gt;icmp permit any echo outside&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;icmp permit any time-exceeded outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 19:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907028#M457323</guid>
      <dc:creator>Roman Rodichev</dc:creator>
      <dc:date>2012-04-05T19:47:00Z</dc:date>
    </item>
    <item>
      <title>Ping allowed but not configured</title>
      <link>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907029#M457324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roman,&lt;/P&gt;&lt;P&gt;I appreciate the reply but neither of those commands are configured on the ASA and there are no inspect statements allowing icmp and only the implicit deny access rule is configured on the outside interface so I'm still confused as to what is allowing the pings to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 19:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907029#M457324</guid>
      <dc:creator>jeff6strings</dc:creator>
      <dc:date>2012-04-05T19:50:34Z</dc:date>
    </item>
    <item>
      <title>Ping allowed but not configured</title>
      <link>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907030#M457325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a test on my home ASA 5505 8.4(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that if you dont have any "icmp permit/deny" lines configured (ASA default?), the ASA will respond to ICMP from anywhere on the corresponding interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you lets say add one line to allow ICMP to the ASA outside interface and you're pinging from some other network thats not mentioned in the rule you just inserted, the ASA wont respond.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it seems to be&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;No "icmp permit/deny" statements = all ICMP allowed&lt;/LI&gt;&lt;LI&gt;1 or more ICMP statement configured to the interface = only that network/host is allowed to ping interface. Rest are blocked&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be honest I dont know what this is based on but it does seem to work like that after I tried the commands around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 20:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907030#M457325</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-04-05T20:10:01Z</dc:date>
    </item>
    <item>
      <title>Ping allowed but not configured</title>
      <link>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907031#M457326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jouni, thanks for the reply as I was under the impression the ASA denies icmp by default unless manually allowed. Either there is something I'm missing or we have bug based on version and/or configuration we have or I'm wrong assuming pings are denied by default.&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 20:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907031#M457326</guid>
      <dc:creator>jeff6strings</dc:creator>
      <dc:date>2012-04-05T20:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ping allowed but not configured</title>
      <link>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907032#M457327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pings to the interface are permitted by default.  Pings through the asa are denied by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Apr 2012 03:38:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-allowed-but-not-configured/m-p/1907032#M457327</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2012-04-06T03:38:45Z</dc:date>
    </item>
  </channel>
</rss>

