<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: %ASA-4-313005: No matching connection for ICMP error message in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395774#M857304</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Das&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its good to have ICMP disabled from outside... you should not have it open unless it is highly essential.. even if it is, its better to disable.. what are the ip addresses shown in the log message ? Is it anything related to your network ? Do you have IPS or CSMARs on your network ? These devices can actually inspect packets on application layer and see if there are any vulnerabilities or attacks on the packets entering your network...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Feb 2010 16:15:48 GMT</pubDate>
    <dc:creator>sachinraja</dc:creator>
    <dc:date>2010-02-02T16:15:48Z</dc:date>
    <item>
      <title>%ASA-4-313005: No matching connection for ICMP error message:</title>
      <link>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395771#M857275</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'd like to understand what this message means:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 02 2010 16:30:14 PROD : %ASA-4-313005: No matching connection for ICMP error message: icmp src outside:1.1.1.1 dst vlan_inside:2.2.2.2 (type 3, code 3) on outside interface.&amp;nbsp; Original IP payload: udp src 2.2.2.2/53 dst 1.1.1.1/49462.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a ASA and behind some DNS. Often i see message below and i cannot understand why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;may anyone can help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tnx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Das&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395771#M857275</guid>
      <dc:creator>danilodicesare</dc:creator>
      <dc:date>2019-03-11T17:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: %ASA-4-313005: No matching connection for ICMP error message</title>
      <link>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395772#M857295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Das&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you allowed ICMP between the zones ? This just shows that ICMP is dropped between the IP addresses specified.. this is just a warning message .. the session may not be established, but need to have a look on the sourcen and destination IPs given in the error.. do you see the source/destination on your network ? Are you getting too many of these, or just once in a while ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Feb 2010 15:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395772#M857295</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2010-02-02T15:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: %ASA-4-313005: No matching connection for ICMP error message</title>
      <link>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395773#M857299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've got a lot of those and i think icmp is allowed from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Das&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Feb 2010 15:55:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395773#M857299</guid>
      <dc:creator>danilodicesare</dc:creator>
      <dc:date>2010-02-02T15:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: %ASA-4-313005: No matching connection for ICMP error message</title>
      <link>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395774#M857304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Das&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its good to have ICMP disabled from outside... you should not have it open unless it is highly essential.. even if it is, its better to disable.. what are the ip addresses shown in the log message ? Is it anything related to your network ? Do you have IPS or CSMARs on your network ? These devices can actually inspect packets on application layer and see if there are any vulnerabilities or attacks on the packets entering your network...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Feb 2010 16:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395774#M857304</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2010-02-02T16:15:48Z</dc:date>
    </item>
    <item>
      <title>%ASA-4-313005: No matching connection for ICMP error message:</title>
      <link>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395775#M857309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am also having this message on our ASA, we have no idea of the IP address which is trying to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a Cisco refernce to these syslog outpus?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 20:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395775#M857309</guid>
      <dc:creator>John Peterson</dc:creator>
      <dc:date>2012-06-13T20:19:22Z</dc:date>
    </item>
    <item>
      <title>Hi,This is a 4-year old</title>
      <link>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395776#M857315</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is a 4-year old question, yet it comes up top of a relevant Google search, so it might be worth trying to answer:&lt;/P&gt;&lt;P&gt;Search for "%ASA-4-313005" on this page,&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/15246-31.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/15246-31.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;to see what Cisco has to say about it (admittedly for a PIX, but the dame applies to ASA's).&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the background as to what may be happening look here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://silviocesare.wordpress.com/2007/10/20/icmp-destination-unreachable/"&gt;http://silviocesare.wordpress.com/2007/10/20/icmp-destination-unreachable/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;On the whole, it's actually a bad idea categorically to deny incoming ICMP messages; echo-reply should certainly be allowed (so that people can ping) but some other ICMP's, including most "unreachable" messages, should also be allowed, particularly if you user community is technical and wants to do things like traceroutes.&amp;nbsp; Also, maximum-MSS negotiation - crucial for proper functioning of TCP - relies on "ICMP unreachable" control messages.&lt;/P&gt;&lt;P&gt;So, follow Cisco's advice and block the attacking address.&amp;nbsp; That is a good way to get rid of the log messages without actually disabling message type 313005 altogether.&amp;nbsp; The traffic itself is blocked anyway - that's what the firewall already did for you, and why it wrote a log message!&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 19:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395776#M857315</guid>
      <dc:creator>m.sohnius</dc:creator>
      <dc:date>2014-03-13T19:38:09Z</dc:date>
    </item>
    <item>
      <title>I am seeing this too.So it</title>
      <link>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395777#M857321</link>
      <description>&lt;P&gt;I am seeing this too.&lt;/P&gt;&lt;P&gt;So it goes out as ICMP and returns UDP?????&lt;/P&gt;&lt;P&gt;udp src 2.2.2..................&lt;/P&gt;&lt;P&gt;icmp src outside:...............&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this why the ASA can't find a match?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2015 20:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-4-313005-no-matching-connection-for-icmp-error-message/m-p/1395777#M857321</guid>
      <dc:creator>Vern Brinkman</dc:creator>
      <dc:date>2015-07-01T20:12:51Z</dc:date>
    </item>
  </channel>
</rss>

