cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
811
Views
10
Helpful
3
Replies

How ASA Handles PING Traffic

Hi Experts,

 

 Could you please assist with how ASA handles ping. I've seen in docs that if Asa wants to allow Ping THROUGH the firewall , Icmp inspection needs to be enabled. Is that fine or we need to allow ACL as well to work.

 

Also, please guide how Asa handles Icmp traffic generated FROM the firewall (Ex. from ASA to Inside/outside) hosts

 

 

Regards,

Srinivasan

1 Accepted Solution

Accepted Solutions

Dennis Mink
VIP Alumni
VIP Alumni

its actually pretty simple. if you allow icmp from inside to out (either with or without an ACL) the icmp inspection will dynamically allow the echo reply back to the source of the ping. if you trun icmp inspection off, the you would need to explicitly permit icmp echo replies back in. I hope that explains it.

Please remember to rate useful posts, by clicking on the stars below.

View solution in original post

3 Replies 3

Dennis Mink
VIP Alumni
VIP Alumni

its actually pretty simple. if you allow icmp from inside to out (either with or without an ACL) the icmp inspection will dynamically allow the echo reply back to the source of the ping. if you trun icmp inspection off, the you would need to explicitly permit icmp echo replies back in. I hope that explains it.

Please remember to rate useful posts, by clicking on the stars below.

Hi Dennis,  Thanks for the reply. Please assist  by default to which zone (Inside/Outside/DMZ) ICMP ping is allowed when traffic is initiated FROM ASA firewall.

When you initiate icmp (or other) traffic from the firewall itself, it will be allowed (absent an (uncommon) output ACL) and sourced from the interface which is the current egress for the destination per the ASA's routing table.

Review Cisco Networking for a $25 gift card