<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5525 ICMP Bypass not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765052#M8360</link>
    <description>&lt;P&gt;Hello everyone. I have a problem that has to be solved immediately. I took photo from cisco webpage that is identical to my design on particular interface. just the ip addresses are different but i will ask using ip addresses in the photo.&lt;/P&gt;
&lt;P&gt;So requirement is this way:&lt;/P&gt;
&lt;P&gt;192.168.1.10 &amp;lt;---&amp;gt; 192.168.2.10 ICMP&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;192.168.1.10 &amp;lt;---&amp;gt; 192.168.2.10&amp;nbsp;80&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;192.168.1.10 &amp;lt;---&amp;gt; 192.168.2.10&amp;nbsp;443&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But as you already understood initial traffic goes from router into server directly and answer comes through ASA and it creates problem. I permitted all possible reply traffic for all 3 protocol. And bypassed each of them through service policy. HTTP and HTTPS worked properly but 192.168.1.10 cannot ping 192.168.2.10. I tried different access-lists but no result. Finally i even permitted traffic from 192.168.2.10 into 192.168.1.10 with IP services and bypassed all IP services but ping still not working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In my case 192.168.2.10 is 10.124.49.5 and 192.168.1.10 is 10.124.41.104. As you see from ss that even acl hits are recorded. But ping is not working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What can be a problem?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:34:56 GMT</pubDate>
    <dc:creator>orkhan.rustamli.96</dc:creator>
    <dc:date>2020-02-21T16:34:56Z</dc:date>
    <item>
      <title>ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765052#M8360</link>
      <description>&lt;P&gt;Hello everyone. I have a problem that has to be solved immediately. I took photo from cisco webpage that is identical to my design on particular interface. just the ip addresses are different but i will ask using ip addresses in the photo.&lt;/P&gt;
&lt;P&gt;So requirement is this way:&lt;/P&gt;
&lt;P&gt;192.168.1.10 &amp;lt;---&amp;gt; 192.168.2.10 ICMP&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;192.168.1.10 &amp;lt;---&amp;gt; 192.168.2.10&amp;nbsp;80&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;192.168.1.10 &amp;lt;---&amp;gt; 192.168.2.10&amp;nbsp;443&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But as you already understood initial traffic goes from router into server directly and answer comes through ASA and it creates problem. I permitted all possible reply traffic for all 3 protocol. And bypassed each of them through service policy. HTTP and HTTPS worked properly but 192.168.1.10 cannot ping 192.168.2.10. I tried different access-lists but no result. Finally i even permitted traffic from 192.168.2.10 into 192.168.1.10 with IP services and bypassed all IP services but ping still not working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In my case 192.168.2.10 is 10.124.49.5 and 192.168.1.10 is 10.124.41.104. As you see from ss that even acl hits are recorded. But ping is not working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What can be a problem?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765052#M8360</guid>
      <dc:creator>orkhan.rustamli.96</dc:creator>
      <dc:date>2020-02-21T16:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765060#M8361</link>
      <description>&lt;P&gt;Hi Orkhan,&lt;/P&gt;
&lt;P&gt;enable ICMP inspection in service policy.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://www.petenetlive.com/KB/Media/0000351/00001s.jpg" border="0" alt="ASDM ping" /&gt;&lt;/P&gt;
&lt;P&gt;ref -&amp;nbsp;&lt;A href="https://www.petenetlive.com/KB/Article/0000351" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0000351&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful responses ***&lt;BR /&gt;Good Luck&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 14:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765060#M8361</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2018-12-17T14:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765074#M8362</link>
      <description>Already enabled&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Dec 2018 14:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765074#M8362</guid>
      <dc:creator>orkhan.rustamli.96</dc:creator>
      <dc:date>2018-12-17T14:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765080#M8363</link>
      <description>1 - try enabling ICMP protocol in ACLs &lt;BR /&gt;2 - allow intra and inter same security level traffic</description>
      <pubDate>Mon, 17 Dec 2018 14:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765080#M8363</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2018-12-17T14:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765132#M8364</link>
      <description>&lt;P&gt;As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt; suggested enter the command - &lt;EM&gt;&lt;STRONG&gt;same-security-traffic permit intra-interface &lt;/STRONG&gt;&lt;/EM&gt;this is because you are routing to/from the same inside interface.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 15:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765132#M8364</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-12-17T15:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765156#M8365</link>
      <description>That is also done&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Dec 2018 16:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765156#M8365</guid>
      <dc:creator>orkhan.rustamli.96</dc:creator>
      <dc:date>2018-12-17T16:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765172#M8366</link>
      <description>what is the OS you are using on http server? try turn off the Host firewall. may be its blocking the ping reply.</description>
      <pubDate>Mon, 17 Dec 2018 16:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765172#M8366</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2018-12-17T16:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765204#M8367</link>
      <description>As it seems from photos i enabled acl and inter and intra&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Dec 2018 16:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765204#M8367</guid>
      <dc:creator>orkhan.rustamli.96</dc:creator>
      <dc:date>2018-12-17T16:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765515#M8368</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;you can enable them as below capture. you can tick them and apply. also disable Host firewall in server.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://checkthenetwork.com/Content/Images/uploaded/security-cisco-asa-asdm-1.jpg" border="0" alt="Image result for enable same security traffic asa asdm" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 03:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765515#M8368</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2018-12-18T03:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765549#M8369</link>
      <description>&lt;P&gt;I do not think that problem with OS of the server. Host Firewalls are disabled. When i disable ICMP inspection from global policy ping works. I mean my problem is that when inspection is enabled bypass settings not working for icmp traffic but works for tcp. All inter,intra, acl confs are done beforehand&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 05:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765549#M8369</guid>
      <dc:creator>orkhan.rustamli.96</dc:creator>
      <dc:date>2018-12-18T05:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 ICMP Bypass not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765559#M8370</link>
      <description>&lt;P&gt;Soo, I can solve the problem by disabling inspection from global policy. Creating new class unders global policy map which no matching interesting traffic and matching any any and inspect. This way i eleminated by reply traffic from inspection and all other stuff still inspected&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 05:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-icmp-bypass-not-working/m-p/3765559#M8370</guid>
      <dc:creator>orkhan.rustamli.96</dc:creator>
      <dc:date>2018-12-18T05:41:35Z</dc:date>
    </item>
  </channel>
</rss>

