<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ICMP redirect in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669577#M536863</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I would like how I can allow the ICMP Redirect ( type 5 ) on my ASA LAN Interface.&lt;/P&gt;&lt;P&gt;PC from LAN have ASA LAN interface as gateway and have to join another Router behind.&lt;/P&gt;&lt;P&gt;I need to allow this traffic.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:53:18 GMT</pubDate>
    <dc:creator>beaujoire</dc:creator>
    <dc:date>2019-03-11T20:53:18Z</dc:date>
    <item>
      <title>ICMP redirect</title>
      <link>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669577#M536863</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I would like how I can allow the ICMP Redirect ( type 5 ) on my ASA LAN Interface.&lt;/P&gt;&lt;P&gt;PC from LAN have ASA LAN interface as gateway and have to join another Router behind.&lt;/P&gt;&lt;P&gt;I need to allow this traffic.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669577#M536863</guid>
      <dc:creator>beaujoire</dc:creator>
      <dc:date>2019-03-11T20:53:18Z</dc:date>
    </item>
    <item>
      <title>ICMP redirect</title>
      <link>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669578#M536864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the old times, icmp redirect is blocked by default on the ASA. I think you can not allow it. You can put as default gateway the other inside Router, and then have a default route on this router to point back to the ASA inside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2011 11:02:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669578#M536864</guid>
      <dc:creator>p.charalambous1</dc:creator>
      <dc:date>2011-06-30T11:02:43Z</dc:date>
    </item>
    <item>
      <title>ICMP redirect</title>
      <link>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669579#M536865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Client Must have ASA interface as default Gateway,I can't change it with default gateway of the inside Router.&lt;/P&gt;&lt;P&gt;This is my topology :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server (192.168.4.20) ---- (4.229) Router (.1.229) ----- (1.254)(IN) ASA (OUT)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PC - 192.168.1.108&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gw : 192.168.1.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've just read this Post : &lt;A _jive_internal="true" href="https://community.cisco.com/message/3290683#3290683"&gt;https://supportforums.cisco.com/message/3290683#3290683&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Its seems to be similar to my Problem.&lt;/P&gt;&lt;P&gt;I don't understand the solution to split the network in two and add routes to the inside router.&lt;/P&gt;&lt;P&gt;However I will try the TCP bypass Solution.&lt;/P&gt;&lt;P&gt;Or Maybe I can add a batch script on the Client,it would be someting like that: &lt;/P&gt;&lt;P&gt;192.168.4.0 255.255.255.0 192.168.1.229 1&amp;nbsp; By this way,I could keep the default Gateway and traffic will avoid to access trought the ASA interface.isn't it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2011 13:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669579#M536865</guid>
      <dc:creator>beaujoire</dc:creator>
      <dc:date>2011-06-30T13:10:37Z</dc:date>
    </item>
    <item>
      <title>ICMP redirect</title>
      <link>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669580#M536866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; No one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 13:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669580#M536866</guid>
      <dc:creator>beaujoire</dc:creator>
      <dc:date>2011-07-05T13:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP redirect</title>
      <link>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669581#M536867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Thomas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this from global config mode:&lt;/P&gt;&lt;P&gt;&amp;nbsp; icmp permit any 5 &lt;INSIDE interface="" name=""&gt;&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; route &lt;INSIDE interface="" name=""&gt; 192.168.4.0 255.255.255.0 192.168.1.229&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt; end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, if it a matter of just that single PC, you can install a permanent route on it to the 192.168.4.0/24 network:&lt;/P&gt;&lt;P&gt; - If it is a Win machine: &lt;SPAN style="text-decoration: underline;"&gt;route -p add 192.168.4.0 mask 255.255.255.0 192.168.1.229&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; - If Linux or other *NIX: &lt;SPAN style="text-decoration: underline;"&gt;/sbin/route add -net 192.168.4.0 netmask 255.255.255.0 gw 192.168.1.229&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;both commands would require either Administrative or su privileges.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH/Regards,&lt;/P&gt;&lt;P&gt;Vasil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 16:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669581#M536867</guid>
      <dc:creator>vmilanov</dc:creator>
      <dc:date>2011-07-05T16:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP redirect</title>
      <link>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669582#M536868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I' ve add the command. It's still the same,the packet is denied. I joined the Packet Tracert Log.&lt;/P&gt;&lt;P&gt;I need to access network 4.0 from different clients in the LAN.I will test the TCP Bypass Option or add the route in the Logon script if the ICMP redirect cann't work with ASA .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/5/2/52256-fffff.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jul 2011 08:40:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-redirect/m-p/1669582#M536868</guid>
      <dc:creator>beaujoire</dc:creator>
      <dc:date>2011-07-06T08:40:31Z</dc:date>
    </item>
  </channel>
</rss>

