cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
391
Views
0
Helpful
2
Replies

doubt about access-list

giovannibaldi
Level 1
Level 1

Hello guys, i need an help. Could you tell me If when i deny IP traffico towards an host  i deny also icmp traffic?

Tanks gio

2 Replies 2

 

 

This is incorrect.  the ICMP protocol is part of the IP protocol suite and is used to send error messages.  So in denying IP you will also be denying ICMP.

But also keep in mind that the ICMP request and ICMP reply are two different flows and are not tracked in the state table of the ASA.  So, if you are pinging from a device on a higher security level interface to a device on a lower security level interface the reply will be denied unless specifically permitted.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card