cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
999
Views
0
Helpful
3
Replies

block icmp never work on ASA 8.6

Neetu Bhushan
Level 1
Level 1

hi all,

i tried putting this on my ACL

access-list outside_access_in line 1 extended deny icmp any any echo

and write it on the flash.

but still i can ping my ip address.  my ASA version is 8.6.

thanks for any comment you may add.

1 Accepted Solution

Accepted Solutions

James Leinweber
Level 4
Level 4

The access-list plus access-group apply to traffic transiting through the ASA, not directed to the ASA itself.  To block icmp to the ASA use instead an icmp deny ... statement.

-- Jim Leinweber, WI State Lab of Hygiene

View solution in original post

3 Replies 3

James Leinweber
Level 4
Level 4

The access-list plus access-group apply to traffic transiting through the ASA, not directed to the ASA itself.  To block icmp to the ASA use instead an icmp deny ... statement.

-- Jim Leinweber, WI State Lab of Hygiene

thanks i got it....

icmp deny any echo-reply outside

actually this also makes my pinging from inside to outside, not possible.

so this answer is not correct...

Review Cisco Networking for a $25 gift card