<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do ASA clusters support inspect icmp? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3383922#M957912</link>
    <description>ICMP inspection is supported in cluster deployment. Advanced inspections&lt;BR /&gt;such as h323 and sccp aren't supported.&lt;BR /&gt;&lt;BR /&gt;You won't see dynamic ACLs created for inspection.&lt;BR /&gt;&lt;BR /&gt;However, I have seem some bugs related to ICMP in ASA cluster with PAT&lt;BR /&gt;</description>
    <pubDate>Wed, 16 May 2018 05:21:02 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2018-05-16T05:21:02Z</dc:date>
    <item>
      <title>Do ASA clusters support inspect icmp?</title>
      <link>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3383864#M957911</link>
      <description>&lt;P&gt;Do ASA clusters support inspect icmp?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This document lists several inspections that are and are not supported.&amp;nbsp; However it is silent regarding icmp&amp;nbsp;inspections.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_cluster.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_cluster.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our ASA cluster allows us to configure the inspect icmp&amp;nbsp;but it doesn't seem to work.&amp;nbsp; &amp;nbsp; We get nothing in logs about creating dynamic ACLs and we can only get our pings to work if we configured a static ACL on the outside--&amp;gt;in to permit echo-reply.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3383864#M957911</guid>
      <dc:creator>Tod Larson</dc:creator>
      <dc:date>2020-02-21T15:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Do ASA clusters support inspect icmp?</title>
      <link>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3383922#M957912</link>
      <description>ICMP inspection is supported in cluster deployment. Advanced inspections&lt;BR /&gt;such as h323 and sccp aren't supported.&lt;BR /&gt;&lt;BR /&gt;You won't see dynamic ACLs created for inspection.&lt;BR /&gt;&lt;BR /&gt;However, I have seem some bugs related to ICMP in ASA cluster with PAT&lt;BR /&gt;</description>
      <pubDate>Wed, 16 May 2018 05:21:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3383922#M957912</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-05-16T05:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Do ASA clusters support inspect icmp?</title>
      <link>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3384033#M957913</link>
      <description>This is good news!&lt;BR /&gt;Now somehow related to this: why doesn't regular ASAs (9.6 code for example) support stateful ICMP?&lt;BR /&gt;I am still puzzled about traceroute requirement to allow time-exceeded on the outside interface as long as I allow it ORIGINALLY on the inside interface.</description>
      <pubDate>Wed, 16 May 2018 09:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3384033#M957913</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-05-16T09:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Do ASA clusters support inspect icmp?</title>
      <link>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3384306#M958029</link>
      <description>&lt;P&gt;We retested inspect ICMP today on our ASA cluster and it worked fine today.&amp;nbsp; Yesterday we must have done a bad test.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any show command that will tell us that ICMP echo-replies are being serviced by the inspection engine?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 15:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-asa-clusters-support-inspect-icmp/m-p/3384306#M958029</guid>
      <dc:creator>Tod Larson</dc:creator>
      <dc:date>2018-05-16T15:24:42Z</dc:date>
    </item>
  </channel>
</rss>

