<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP Errors on ASA 5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550896#M685255</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick response!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no idea what's at 66.114.54.32. It is external to our network. There are hundreds of these warnings and the destination address in the original payload vary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason (by design?) I can't do any traceroutes from workstations on our network to external hosts, but I can traceroute from a router beyond our ASA to the above IP address. And I know that our Internet provider (our county office of education) blocks ping, but these facts my not play into this matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Nov 2010 18:57:12 GMT</pubDate>
    <dc:creator>Mark Wagnon</dc:creator>
    <dc:date>2010-11-09T18:57:12Z</dc:date>
    <item>
      <title>ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550894#M685244</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I started poking around our ASA 5520 (I seem to have inherited the job of administrating it) and I'm seeing the following messages intermixed in the syslog:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Denied ICMP type=3, code=13 from 10.35.200.9 on interface Outside&lt;BR /&gt;No matching connection for ICMP error message: icmp src Outside:10.35.200.9 dst identity:10.35.1.2 (type 3, code 13) on Outside interface.&amp;nbsp; Original IP payload: icmp src 10.35.1.2 dst 66.114.54.32 (type 0, code 0).&lt;BR /&gt;Deny icmp src Outside:10.35.200.9 dst Inside:10.35.1.2 (type 3, code 13) by access-group "Outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know which preceeds the other, but they are occurring at a rate of 20-30 or so per minute. A little about the IP addresses above:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.35.200.9: this is the ip route set on our edge/Internet router. I'm assuming it's on the router for our Opt-e-man hand-off.&lt;BR /&gt;10:35.1.2: this is the outside interface on our ASA&lt;BR /&gt;66.114.54.32: Not sure what this is, something called Panther Express.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know if this is something normal to see on the ASA or what is even going on here. From what I've read, the ICMP type 3, code 13 message means that the destination is unreachable due to an administrative setting to prohibit communication. Any thoughts on if I should be worried?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;BR /&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550894#M685244</guid>
      <dc:creator>Mark Wagnon</dc:creator>
      <dc:date>2019-03-11T19:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550895#M685248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It means that the firewall was sending packets to 66.114.54.32 and this guy 10.35.200.9 told him that it is not reachable. It would be better for you to find out what is&amp;nbsp; 66.114.54.32.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that some kind of SNMP server or something like that? Can you check it on your configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 18:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550895#M685248</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-11-09T18:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550896#M685255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick response!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no idea what's at 66.114.54.32. It is external to our network. There are hundreds of these warnings and the destination address in the original payload vary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason (by design?) I can't do any traceroutes from workstations on our network to external hosts, but I can traceroute from a router beyond our ASA to the above IP address. And I know that our Internet provider (our county office of education) blocks ping, but these facts my not play into this matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 18:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550896#M685255</guid>
      <dc:creator>Mark Wagnon</dc:creator>
      <dc:date>2010-11-09T18:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550897#M685268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct, Have you go through the config to check if that IP address is there? Do you have any aplication on the inside that uses ICMP messages in order to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 19:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550897#M685268</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-11-09T19:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550898#M685288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;BTW, the 66.x.x.x. ip seems to be &lt;STRONG&gt;ns2.panthercdc.com.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I am not sure if that rings a bell to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 19:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550898#M685288</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-11-09T19:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550899#M685299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I went through the configs on our ASA and the edge router and that IP address is not listed in either config. As far as applications needing ICMP to function, we don't have any that I know of. I guess I'm kind of wondering why our ASA is trying to talk to these IPs or if it's just trying to forward traffic normally and being told by the host at 10.35.200.9 that those destinations are unreachable for whatever reason. I do not have access to the 10.35.200.9 device though. Funny thing is, I can traceroute from a router that sits between our ASA and the 10.35.200.9 router. Interesting. Thanks for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;mayrojas wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct, Have you go through the config to check if that IP address is there? Do you have any aplication on the inside that uses ICMP messages in order to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 20:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550899#M685299</guid>
      <dc:creator>Mark Wagnon</dc:creator>
      <dc:date>2010-11-09T20:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550900#M685315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I get the following when I do a nslookup for that IP: mia-agg-n22.panthercdn.com. It's not one of our hosts, and it's external to us, so no bells rung here. The IP addresses vary and it was just by chance I selected that IP as I copied a section from the log at random. Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;pkampana wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, the 66.x.x.x. ip seems to be &lt;STRONG&gt;ns2.panthercdc.com.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I am not sure if that rings a bell to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 20:09:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550900#M685315</guid>
      <dc:creator>Mark Wagnon</dc:creator>
      <dc:date>2010-11-09T20:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550901#M685337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing that occurs to me is the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-The ASA itself tries to located someone on the outside world (doing queries to DNS or whatever) he does not get a respond and the guys on the internet are telling you that they cannot reach it. These packets are denied have a deny icmp any outside (you can check that doing sh run icmp).&lt;/P&gt;&lt;P&gt;2-Someone on the inside trying to reach any of those host, and the same story happens (of course this would happen only in case you are running PAT).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 20:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550901#M685337</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-11-09T20:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550902#M685351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Options 1 sounds more like what is happening because we're not using PAT. When I issue sh run icmp, I get "icmp unreachable rate-limit 1 burst-size 1". Our issue seems to be normal activity then? I just want to make sure that we're not experiencing any issues or even worse causing them for someone else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;mayrojas wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing that occurs to me is the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-The ASA itself tries to located someone on the outside world (doing queries to DNS or whatever) he does not get a respond and the guys on the internet are telling you that they cannot reach it. These packets are denied have a deny icmp any outside (you can check that doing sh run icmp).&lt;/P&gt;&lt;P&gt;2-Someone on the inside trying to reach any of those host, and the same story happens (of course this would happen only in case you are running PAT).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 23:33:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550902#M685351</guid>
      <dc:creator>Mark Wagnon</dc:creator>
      <dc:date>2010-11-09T23:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Errors on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550903#M685363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am pretty confident that you are not causing any damage to anyone, but sniffing the packets or knowing the source of this would be nice.This may also be something related to your ISP blocking ICMP messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 00:04:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-errors-on-asa-5520/m-p/1550903#M685363</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-11-10T00:04:38Z</dc:date>
    </item>
  </channel>
</rss>

