cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
463
Views
0
Helpful
1
Replies

ICMP Inspection

George D
Level 1
Level 1

How can I allow outbound ICMP but prevent a remote shell exploit such as this:

http://resources.infosecinstitute.com/icmp-reverse-shell/#gref

1 Reply 1

johnlloyd_13
Level 9
Level 9

hi,

you can configure ICMP inspection under global policy map.

this will let the ASA create a state table and remember who's making ping request from the 'inside' or trusted interface.

policy-map global_policy
 class inspection_default
  inspect icmp
  inspect icmp error

Review Cisco Networking for a $25 gift card