<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP being allowed through?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125969#M893892</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Nov 2008 22:12:33 GMT</pubDate>
    <dc:creator>John Blakley</dc:creator>
    <dc:date>2008-11-06T22:12:33Z</dc:date>
    <item>
      <title>ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125959#M893876</link>
      <description>&lt;P&gt;I can't understand this one. I have a netopia router in front of an ASA. The ASA is getting an address from the provider for the time being, but I can ping that address. In my logs I see where the icmp connection is being built and torn down on the ASA, but it's from a different ip than mine. Is it possible that I'm hitting the netopia router and it's responding for the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:09:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125959#M893876</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2019-03-11T14:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125960#M893878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you provide a bit of addressing - doesn't have to be the real addressing just use any addressing to give example. Is it &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN -&amp;gt; ASA -&amp;gt; Netopia router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so could you provide addressing for interfaces and also where you are pinging from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean when you say ASA ia getting address from provider - do you mean DHCP ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 21:19:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125960#M893878</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T21:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125961#M893880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a pppoe account that's assigned an address. The current layout is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN --&amp;gt; ASA --&amp;gt; Netopia --&amp;gt; Cloud&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA public is 192.168.1.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Netopia is supposedly in bridging mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my box (outside of their network), I can ping 192.168.1.5. In the logs I see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-6-302020: Built inbound ICMP connection for faddr 1.1.1.1 (my public)/37737 gaddr&lt;/P&gt;&lt;P&gt;192.168.1.5/0 laddr 192.168.1.5/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This makes NO sense. I don't have ACLs that are allowing the traffic through, and I was always under the assumption that the public side always dropped any traffic unless explicitly permitted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 21:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125961#M893880</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2008-11-06T21:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125962#M893882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry it's been a long day so i may be a bit slow ! You are pinging from another public IP address, nothing to do with the LAN behind the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so an acl on the outside interface of the ASA does not control whether you can ping the outside interface but whether ICMP is allowed through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look in the ASA config to see if there is a line &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, apologies if i am still not understanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 21:42:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125962#M893882</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T21:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125963#M893883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's understandable...it has been a LONG day &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm pinging from one public to another public (outside interface on ASA). There's no icmp lines on there, and to verify I did the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list TEST deny icmp any any&lt;/P&gt;&lt;P&gt;access-list TEST permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group TEST in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can still ping with no hits on the acl. I believe the Netopia is answering for the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 21:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125963#M893883</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2008-11-06T21:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125964#M893885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay i need some sleep &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm pinging from one public to another public (outside interface of ASA) - yes but where from a topology point of view is the other public IP ie. the public IP that is not the outside interface of the ASA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 21:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125964#M893885</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T21:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125965#M893886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's in another state &lt;span class="lia-unicode-emoji" title=":monkey_face:"&gt;🐵&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It connects to us through easyvpn. I thought that was the problem, so I remoted into one of my laptops at my house, and I could ping it from there too. The ASA is just another device out on the internet. Does that help? It really makes no sense, and it's frustrating me. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I don't get frustrated easily.... LOL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 22:05:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125965#M893886</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2008-11-06T22:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125966#M893887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lets use a bit of inverse logic. On your ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)# icmp deny any outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 22:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125966#M893887</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T22:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125967#M893889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;LOL! That worked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Now, why won't my acl block it?? It wasn't even touching my acl.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 22:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125967#M893889</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2008-11-06T22:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125968#M893891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think we have both had it today. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your acl has no effect on ICMP traffic going to an interface on the ASA. An acl only effects ICMP traffic (and all other traffic) going through the ASA from one side to another.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default must be to allow icmp but to all interfaces but it didn't used to be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 22:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125968#M893891</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T22:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP being allowed through??</title>
      <link>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125969#M893892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 22:12:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-being-allowed-through/m-p/1125969#M893892</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2008-11-06T22:12:33Z</dc:date>
    </item>
  </channel>
</rss>

