cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
464
Views
0
Helpful
4
Replies

ASA dropping packets to internet

nikmagashi1
Level 1
Level 1

Hi,

I have configured an access rule like below:

nikmagashi1_0-1677158081500.png

but when I am doing a packet tracer on this rule I am getting denied by the implicit policy:

nikmagashi1_1-1677158177484.png

Am I missing something?

 

4 Replies 4

select port in packet-tracer and check again.
also try ping from any host in lan to 8.8.8.8 
then try ping from any host in lan to google.com 
check if the issue is the DNS resolve in ASA 

nikmagashi1
Level 1
Level 1

I do not have any clients right now to test for real but I was just using the packet tracer tool to see if the traffic is allowed or not. Now it is flowing according to the packet tracer and because I have other rules for the same interface and at the bottom of it the rule for internet, I created another rule just above the internet rule to deny anything to private addresses (rfc 1918). So I will try to limit the traffic only to those destination we need to.

marly
Level 1
Level 1

hello

If your ASA (Adaptive Security Appliance) is dropping packets to the internet, it could be due to several reasons such as incorrect access control list configuration, routing issues, or NAT problems.                                                                      Nexus Iceland

Troubleshoot by verifying your configuration, reviewing logs, and analyzing traffic flow to identify and resolve the issue.

Let see it will work or not ?

only add port and do packet tracer again 

nikmagashi1_1-1677158177484.png

Review Cisco Networking for a $25 gift card