08-30-2016 07:37 AM - edited 03-12-2019 01:12 AM
I have a cisco ASA 5506-X and want to ping two host. One on the outside interface and one on the inside interface
When i create an access list and appy to it the deny icmp action did not work. The running ping is still ok.
When i stop the ping and restart it after few seconds the asa blocks the icmp.
Why did the access list not work after i appy to it? Only after few seconds and a restart?
Thanks
08-30-2016 08:00 AM
Hello Raimund Schimanovits, you should verify if you must enable ICMP inspection.
08-31-2016 01:29 AM
Is this only for ICMP or should i always inspect to block a traffic for other ports?
08-31-2016 07:08 AM
Hi Raimund Schimanovits, Only for ICMP, if you match correctly source and destination on the ACL, this should work. Also, you can check with packet tracer if traffic is matching with ACL.
Regards.-
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide