cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3962
Views
10
Helpful
7
Replies

Ping from outside to outside interface Firepower 1150

Colin B
Level 1
Level 1

Hello everyone,

I'm unable to ping the outside interface's public IP from the outside. I have ICMP inspection enabled as well as the ACL "icmp permit any outside." I can ping through the device without issue. Looking at the log, it is showing:

- "ICMP error packets were dropped by the ASA because the ICMP error messages are not related to any session already established in the ASA."

I should note, this is one of our VPN servers and the outside interface IP I'm trying to ping is the headend to many ezvpn tunnels. Could that be causing an issue with the way it handles unencrypted traffic on that interface, or is something else goofy going on? 

Thanks!

7 Replies 7

My first question is where are you pinging from?  You might already know this, but you can only ping the ingress interface of the firewall, you will not be able to ping a firewall IP that is not the ing