07-27-2005 09:58 PM - edited 02-21-2020 12:18 AM
Is it possible that icmp type 11 code 0 cause pix to drop traffic?
After
%PIX-3-313001: Denied ICMP type=11, code=0 from x.x.x.6 on interface
inside
access list denies traffic it otherwise passes
08-02-2005 09:50 AM
When using the icmp command with an access list, if the first matched entry is a permit entry, the ICMP packet continues processing. If the first matched entry is a deny entry or an entry is not matched, the firewall discards the ICMP packet and generates this syslog message. The icmp command enables or disables pinging to an interface. With pinging disabled, the firewall cannot be detected on the network. This feature is also referred to as configurable proxy pinging.
08-02-2005 12:00 PM
Problem is that I am using IPSEC tunnels, cca 10 peers. And everything is working ok for 8 12, sometimes for 24 hours. And then tunnels are ... kind of half open. When I look in log all I can see is that ICMP deny message and 10 seconds after fw starts to denies UDP (500), ISAKMP traffic from peers. This is the only what I can see, first that ICMP and 10 secs after problems.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide