<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA ACL issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333962#M857984</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure what you are trying to ping.&lt;/P&gt;&lt;P&gt;Remember, you could not ping from a host in inside network to the ip address of ASA's outside interface. This is an expected behavior.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 26 Sep 2009 05:56:36 GMT</pubDate>
    <dc:creator>Yudong Wu</dc:creator>
    <dc:date>2009-09-26T05:56:36Z</dc:date>
    <item>
      <title>ASA ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333957#M857965</link>
      <description>&lt;P&gt;Greeting All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I`ve tried to ping from the inside network to the outside and in normal case it has to be possible since :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal network has a security profile of 100 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;External network has a security profile of 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And since the rule: Permit from a secure network to a not secure is enabled BUT still i can`t ping from my inside interface (172.16.1.0/24) to the ouside interface (10.10.10.0/24)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I even tried to modify the ACL to allow everything from Inside to the outside and vise versa but still doesn`t work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it a bug or what i`m really stuckk here!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help guys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS: i have attached 2 print screen for more information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:19:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333957#M857965</guid>
      <dc:creator>Seifeddine-Tlili</dc:creator>
      <dc:date>2019-03-11T16:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333958#M857968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have syslog enabled? If yes, what log says about icmp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember by default, ICMP won't be inspected. Therefore, you have to either permit echo-reply on outside interface or enable icmp inspection. Since you have already configured "permit any" on outside interface, you should be able to ping. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If packet was dropped by ASA, you should see something in log or by enable "debug icmp trace 255".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Sep 2009 18:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333958#M857968</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2009-09-25T18:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333959#M857972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your reply i appreciate it,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well in normal case since i have permitted the icmp trafic from the outside to the inside and vise vers ca icmp trafic has to go through but it`s not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have check the packet tracer and it says that the ACL is dropping the packet and it seems that it`s bypassing the rule that i have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached a copy of my run config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly&lt;/P&gt;&lt;P&gt;Seifeddine Tlili&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Sep 2009 19:41:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333959#M857972</guid>
      <dc:creator>Seifeddine-Tlili</dc:creator>
      <dc:date>2009-09-25T19:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333960#M857976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your config looks good. &lt;/P&gt;&lt;P&gt;Can you post the output of packet trace?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Sep 2009 20:01:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333960#M857976</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2009-09-25T20:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333961#M857980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, well it seems that i can`t use a ping with a source address the inside interface to the outside interface however i can ping from an inside host to an outiside host isn`t wierd? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Sep 2009 22:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333961#M857980</guid>
      <dc:creator>Seifeddine-Tlili</dc:creator>
      <dc:date>2009-09-25T22:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333962#M857984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure what you are trying to ping.&lt;/P&gt;&lt;P&gt;Remember, you could not ping from a host in inside network to the ip address of ASA's outside interface. This is an expected behavior.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Sep 2009 05:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-issue/m-p/1333962#M857984</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2009-09-26T05:56:36Z</dc:date>
    </item>
  </channel>
</rss>

