09-26-2014 07:41 AM - edited 03-11-2019 09:49 PM
Hello guys, i need an help. Could you tell me If when i deny IP traffico towards an host i deny also icmp traffic?
Tanks gio
09-28-2014 02:48 AM
09-28-2014 02:48 AM
This is incorrect. the ICMP protocol is part of the IP protocol suite and is used to send error messages. So in denying IP you will also be denying ICMP.
But also keep in mind that the ICMP request and ICMP reply are two different flows and are not tracked in the state table of the ASA. So, if you are pinging from a device on a higher security level interface to a device on a lower security level interface the reply will be denied unless specifically permitted.
--
Please remember to select a correct answer and rate helpful posts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide