cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3728
Views
0
Helpful
2
Replies

ASA log error message 'No matching connection for ICMP error message'

NazgulNr5
Level 1
Level 1

Greetings,

While I was checking the log of our ASA I found error messages like:

No matching connection for ICMP error message: icmp src insideNet:x.x.x.172 dst outside:8.8.8.8 (type 3, code 3) on insideNet interface. Original IP payload: udp src 8.8.8.8/53 dst x.x.x.172/59995.

 

They come in groups of 3-5, every few seconds, all apparently DNS lookups but always from the same host. Before we pull the user over I was wondering if it could be something benign.

 

 

2 Replies 2

steven_dolan7
Level 1
Level 1

This is not a DNS request althought it is destined for Googles DNS address,

 

ICMP is essentially a Ping, 

 

Here is some info on the types of ICMP messages involved.

 

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall-52/Concepts/ICMP%20Types%20and%20Codes.htm

 

Rate if you found this helpfull.

 

Steven

Sorry, not helpfull. I do know what a ping is. Also the error message is not caused by a ping from the inside because then there would be matching connection.

I found one related question:

https://community.cisco.com/t5/firewalls/asa-4-no-matching-connection-for-icmp-error-message/td-p/3805310

Unfortunately I cannot access the upstream router as it belongs to our ISP.

Review Cisco Networking for a $25 gift card