<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Inside users not able to ping to outside interface ip. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756018#M531592</link>
    <description>&lt;P&gt;We are not able to ping&amp;nbsp; to&amp;nbsp; the outside interface of the firewall from inside network (lan network).(ie trafic directed at the interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have executed the command icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; icmp permit any echo outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still we are not able to ping outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also created the accesslist so that the internet user are able to ping to outside interface of the firewall .This is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest so that inside users should be able to ping outside interface.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:21:33 GMT</pubDate>
    <dc:creator>prashantrecon</dc:creator>
    <dc:date>2019-03-11T21:21:33Z</dc:date>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756018#M531592</link>
      <description>&lt;P&gt;We are not able to ping&amp;nbsp; to&amp;nbsp; the outside interface of the firewall from inside network (lan network).(ie trafic directed at the interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have executed the command icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; icmp permit any echo outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still we are not able to ping outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also created the accesslist so that the internet user are able to ping to outside interface of the firewall .This is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest so that inside users should be able to ping outside interface.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:21:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756018#M531592</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2019-03-11T21:21:33Z</dc:date>
    </item>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756019#M531594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prashant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to security features of the ASA, you would never be able to ping remote interfaces on the ASA, which means no ping would work from inside LAN to outside interface and from internet to inside interface. This is not possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would only be able to ping inside interface from LAN, or the default gateway for the firewall, if you are afcing any issues with pinging the internet ip's from the LAN, let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this was useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 10:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756019#M531594</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-07T10:08:54Z</dc:date>
    </item>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756020#M531596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that is the correct default behaviour.&lt;/P&gt;&lt;P&gt;You will not be able to ping the opposite interface of the firewall.&lt;/P&gt;&lt;P&gt;Eg: if your PC is connected to the inside interface, you can only ping the inside interface of the firewall, or anything through the firewall, but not any other interfaces but inside interface of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to ping the firewall outside interface, you can ping it from the internet only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 10:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756020#M531596</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-09-07T10:08:59Z</dc:date>
    </item>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756021#M531600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As mentioned in Richard Deal book he has explained the topic called called trafic directed at the interface .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could u please clear this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 11:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756021#M531600</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2011-09-07T11:14:02Z</dc:date>
    </item>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756022#M531605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prashant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure about what is written in the book, haven't read it but what it may be indicating is the ASA interface to which the LAN machines are connected to. Can you paste the excerpts from the book, because&amp;nbsp; am sure it does not mention anything about the remote interfaces, this is not possible and cannot be done. Do let me know if you have any doubts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 11:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756022#M531605</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-07T11:18:01Z</dc:date>
    </item>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756023#M531610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could u please explain the below concept &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Restricting ICMP Traffic Directed at the Appliance&lt;/P&gt;&lt;P&gt;The remainder of this section will focus on using the ICMP filtering feature. To control&lt;/P&gt;&lt;P&gt;ICMP messages destined to an interface on the appliance, use the icmp command:&lt;/P&gt;&lt;P&gt;ciscoasa(config)# icmp {permit | deny}&lt;/P&gt;&lt;P&gt;src_IP_address src_subnet_mask&lt;/P&gt;&lt;P&gt;[ICMP_message_type] logical_if_name&lt;/P&gt;&lt;P&gt;You must specify a source IP address and a subnet mask. Unlike with an extended ACL,&lt;/P&gt;&lt;P&gt;there is no destination IP address, because the security appliance, itself, is the destination.&lt;/P&gt;&lt;P&gt;You can qualify which ICMP messages are allowed or denied by entering a value for&lt;/P&gt;&lt;P&gt;the ICMP_message_type parameter. The message types can be entered as either a name&lt;/P&gt;&lt;P&gt;or a number. If you omit the message type, the appliance will assume that you want to allow&lt;/P&gt;&lt;P&gt;or deny all ICMP messages. The last parameter is the name of the interface for which&lt;/P&gt;&lt;P&gt;you want to restrict ICMP messages.&lt;/P&gt;&lt;P&gt;The appliance processes the icmp commands top-down for an interface. In other&lt;/P&gt;&lt;P&gt;words, when the appliance receives an ICMP packet destined to one of its interfaces, it&lt;/P&gt;&lt;P&gt;checks to see if any icmp commands are associated with the interface. If none is defined&lt;/P&gt;&lt;P&gt;for the interface, the appliance processes the ICMP message and responds with the appropriate&lt;/P&gt;&lt;P&gt;ICMP response. If an ICMP filter is on the interface, the appliance processes&lt;/P&gt;&lt;P&gt;the icmp commands based on the order in which you entered them. If the appliance goes&lt;/P&gt;&lt;P&gt;through the entire list and doesn’t find a match, the appliance drops the ICMP message;&lt;/P&gt;&lt;P&gt;this is like the implicit deny statement at the end of an ACL.&lt;/P&gt;&lt;P&gt;To remove a specific icmp command, preface it with the no parameter. To delete all the&lt;/P&gt;&lt;P&gt;icmp commands that you have configured, use the clear configure icmp command.&lt;/P&gt;&lt;P&gt;NOTE As with ACLs, an implicit deny is at the end of the icmp command list. Therefore, if you use&lt;/P&gt;&lt;P&gt;the icmp command, you should at least specify one permit statement per interface, unless you&lt;/P&gt;&lt;P&gt;want your appliance to be completely invisible from ICMP traffic on the specified interface.&lt;/P&gt;&lt;P&gt;ICMP Filtering Example&lt;/P&gt;&lt;P&gt;Now let’s take a look at an example on how to use the icmp command to restrict ICMP&lt;/P&gt;&lt;P&gt;messages directed at an appliance interface. In this example, you want to be able to test&lt;/P&gt;&lt;P&gt;connectivity from the appliance to other destinations on the Internet, and you want the&lt;/P&gt;&lt;P&gt;appliance to process only certain ICMP packets to aid in connectivity testing—all other&lt;/P&gt;&lt;P&gt;ICMP messages should be dropped. Here’s an example of how to accomplish this:&lt;/P&gt;&lt;P&gt;ciscoasa(config)# icmp permit any conversion-error outside&lt;/P&gt;&lt;P&gt;ciscoasa(config)# icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;ciscoasa(config)# icmp permit any parameter-problem outside&lt;/P&gt;&lt;P&gt;ciscoasa(config)# icmp permit any source-quench outside&lt;/P&gt;&lt;P&gt;ciscoasa(config)# icmp permit any time-exceeded outside&lt;/P&gt;&lt;P&gt;ciscoasa(config)# icmp permit any unreachable outside&lt;/P&gt;&lt;P&gt;ciscoasa(config)# icmp deny any outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 11:29:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756023#M531610</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2011-09-07T11:29:28Z</dc:date>
    </item>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756024#M531615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prashant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whatever explanation you see in this is for this case, if the host is connected to that interface only, which means:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users on the internet need to ping outside interface&lt;/P&gt;&lt;P&gt;users in the lan need to ping inside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nowhere it is written that you can ping outside interface from the inside network lan, it is only if you are behind that interface. Don't worry you can take our word on this for the Cisco ASA &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 11:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756024#M531615</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-07T11:38:11Z</dc:date>
    </item>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756025#M531620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My doubt is cleared now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 12:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756025#M531620</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2011-09-07T12:14:00Z</dc:date>
    </item>
    <item>
      <title>Inside users not able to ping to outside interface ip.</title>
      <link>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756026#M531624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No issues &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can mark this thread as answered and do rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 12:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-users-not-able-to-ping-to-outside-interface-ip/m-p/1756026#M531624</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-07T12:17:10Z</dc:date>
    </item>
  </channel>
</rss>

