<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5505 - ICMP not responding  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031178#M938746</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Gorge &lt;/P&gt;&lt;P&gt;thank you for your support, but the problem was the version of the handle, I made the update and everything worked. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway thank you very much, we are in contact cuidate goodbye.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 26 Apr 2008 13:58:19 GMT</pubDate>
    <dc:creator>francisco.delgado</dc:creator>
    <dc:date>2008-04-26T13:58:19Z</dc:date>
    <item>
      <title>ASA 5505 - ICMP not responding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031172#M938740</link>
      <description>&lt;P&gt;I am configuring an ASA, but I have no respond when I try to ping to any outside IP address. I have already checked the commands related to ICMP and I have already set those commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is something left still ??? this is the sh  run file.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.2(3)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ipv6 enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address pppoe setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 10.10.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ipv6 enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list ICMPACL extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list DMZ extended permit ip any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;ipv6 icmp permit any DMZ&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-group ICMPACL in interface outside&lt;/P&gt;&lt;P&gt;access-group DMZ in interface DMZ&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 202.38.193.226 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;P&gt;vpdn group pppoe_group request dialout pppoe&lt;/P&gt;&lt;P&gt;vpdn group pppoe_group localname f55xxxxxxxx&lt;/P&gt;&lt;P&gt;vpdn group pppoe_group ppp authentication pap&lt;/P&gt;&lt;P&gt;vpdn username f5512345678 password *********&lt;/P&gt;&lt;P&gt;dhcpd dns 240.x.x.201 200.331.146.193&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.100-192.168.1.150 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map ICMP-CLASS&lt;/P&gt;&lt;P&gt; match access-list ICMPACL&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;policy-map ICMP-POLICY&lt;/P&gt;&lt;P&gt; class ICMP-CLASS&lt;/P&gt;&lt;P&gt;  inspect icmp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031172#M938740</guid>
      <dc:creator>francisco.delgado</dc:creator>
      <dc:date>2019-03-11T12:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 - ICMP not responding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031173#M938741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;to have outside interface respond to ICMP&lt;/P&gt;&lt;P&gt;from the outside add this statement. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#&lt;B&gt;no icmp deny any outside&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to have outside not respond to ICMP from outside place argument back&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#&lt;B&gt;icmp deny any outside&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2008 18:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031173#M938741</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-04-24T18:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 - ICMP not responding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031174#M938742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your comments..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already test that command but it did not worked. I have still the problem of not&lt;/P&gt;&lt;P&gt;having respond when I ping from inside to any outside ip address (public IP addresss)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any other suggestion??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2008 20:25:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031174#M938742</guid>
      <dc:creator>francisco.delgado</dc:creator>
      <dc:date>2008-04-24T20:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 - ICMP not responding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031175#M938743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Francisco, I had understood you were trying to ping the outside interface of firewall from outside, you now indicate you are trying to ping from inside to an outside public IP address if this is the case the process is completely different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping from inside outbound you would need  and access list like this and apply to outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I quote from link&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any source-quench &lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any unreachable  &lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is also recommended to have inspect icmp &lt;/P&gt;&lt;P&gt;which you already have in your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try the above and let us know the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2008 00:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031175#M938743</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-04-25T00:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 - ICMP not responding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031176#M938744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, keep in mind this restriction:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-You can ping the inside interface ip from an inside host.&lt;/P&gt;&lt;P&gt;-You can ping the outside interface ip from an outside host.&lt;/P&gt;&lt;P&gt;-You can NOT ping the outside interface ip from an inside host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Put more generally, you cannot ping the firewall's ip addresses, unless you are on the interface you are pinging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt; -Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2008 19:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031176#M938744</guid>
      <dc:creator>Brian Conklin</dc:creator>
      <dc:date>2008-04-25T19:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 - ICMP not responding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031177#M938745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Brian &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your help &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;already solved my problem, the problem is the version of the asa. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you very much beforehand cuidate goodbye.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Apr 2008 13:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031177#M938745</guid>
      <dc:creator>francisco.delgado</dc:creator>
      <dc:date>2008-04-26T13:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 - ICMP not responding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031178#M938746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Gorge &lt;/P&gt;&lt;P&gt;thank you for your support, but the problem was the version of the handle, I made the update and everything worked. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway thank you very much, we are in contact cuidate goodbye.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Apr 2008 13:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031178#M938746</guid>
      <dc:creator>francisco.delgado</dc:creator>
      <dc:date>2008-04-26T13:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 - ICMP not responding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031179#M938747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me to what version did you upgrade i too have the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Krissh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Apr 2008 20:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-icmp-not-responding/m-p/1031179#M938747</guid>
      <dc:creator>AGINetworkGroup</dc:creator>
      <dc:date>2008-04-26T20:42:08Z</dc:date>
    </item>
  </channel>
</rss>

