09-02-2005 06:37 AM - edited 02-21-2020 12:22 AM
Hy,asa 5510 with 7.0.2 version and icmp echo traffic from dmz host to an outside host and echo-reply from the outside host to dmz host.
If I remove the specific ace of the icmp, the traffic still goes-on even if it remains only the ace "deny ip any any" on the 2 access-lists.
With show conn I can see the 2 icmp sessions.
Why ?
09-02-2005 02:22 PM
i think the reason is due to the fact that icmp fixup is enabled, allowing echo replies to come back
09-03-2005 04:53 AM
Hy, thank you but it runs even if I remove the access-list element that allows the echo.
Could it be related to the new icmp timeout parameter ?
After I have removed the access-list element, if I stop the pc to ping and then I start it again, the new ping is denied.
It seems like the "icmp session" within the timeout is allowed.
Greatings
Renato
09-03-2005 11:02 AM
so for the existing ICMP sessions, they are letting through, but the new sessions will not be.
if you remove the ACL, then do a clear xlat, it will brake your contiuous icmp as well
09-04-2005 11:09 PM
It's true, now how to remove timeout icmp 0:00:02 ?
"no timeout icmp" and "timeout 0:00:00" does not work.
Thank you in advance
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide