04-17-2013 12:54 PM - edited 03-11-2019 06:30 PM
Just installed 7.1(2) and various ICMP ACL rules now have a Red Dot with the number 4 in them. Older version of ASDM (6.x) didn't display this.
Before I start digging through logs I search the manual and didn't see any specific reference. "4" is source quench but I'm not certain (without a manual reference) if that's what the 4 is tied to in this case.
Anybody know what this new display feature is trying to say?
Thanks,
m.
Solved! Go to Solution.
04-22-2013 11:54 AM
Only thing I found related to the icmp and icmp6 was from the Bug Search Tool
Seems to be a enhancement request that was implemented

But again I cant tell from this information if it refers to this situation
This thing is listed on the 7.0(2) ASDM release notes
http://www.cisco.com/en/US/docs/security/asdm/7_0/release/notes/rn70.html#wp461760
- Jouni
04-17-2013 12:57 PM
Hi,
Even though I dont use ASDM almost at all myself, could try to check what its about.
Can you perhaps share a screen capture of the thing you mean (while masking any sensitive information if needed)
- Jouni
04-22-2013 06:50 AM
04-22-2013 07:08 AM
Hi,
Seems it refers to IPv4 and IPv6
Check the below picture

- Jouni
04-22-2013 07:14 AM
ASDM 7.1(x) are expecting to talk to ASA 9.x where the v4 and v6 access rules were unified. Is it trying to tell you that you are looking at a v4-only rule?
-- Jim Leinweber, WI State Lab of Hygiene
04-22-2013 07:43 AM
Both thoughts point to the same reasonable conclusion - I could see value in it.
However, it sin't only ICMP that can have different behaviors depending upon which version of IP they run under. So, maybe ASDM is trying to be extra helpful for ICMP first, or...something else. Didn't see any "6" ever appear, but perhaps that would just mean Cisco/ASDM now considers IPv4 the exception and not the rule ;-}
Anyway, good thoughts and the likely answer, but I'd still like a Cisco documented reference so I can go out with an official explaination...
04-22-2013 09:01 AM
Hi,
I barely use ASDM for any ASA configurations. I tend to configure everything I can through the CLI and therefore I wont be the best person to answer your question.
I would go through the ASDM Release Notes for any specific changes on the ASDM
http://www.cisco.com/en/US/products/ps6121/prod_release_notes_list.html
Also we dont know your exact ASA software version and the ASDM version which you updated from.
- Jouni
04-22-2013 11:25 AM
Thanks but already been through the Release Notes, that's why I posted the question.
ASA Version isn' really the issue - this is a known feature add by Cisco, (presumeably), so, somewhere it must be documented - that's what I'm looking for.
04-22-2013 11:46 AM
Hi,
From what I have seen, Cisco has had a habit of introducing even large changes to device operation without so much as mentioning it in their documentation.
Probably the most common issue I have seen was when people were upgrading their ASA past 8.4(2) software to 8.4(3) for example where the issue was first observed. They decided that ASA would no more populate ARP table with nonconnected networks.
So soon people found that part of their servers worked no more since the ARP behaviour was changed. In the next upgrade they added the command "arp permit-nonconnected" with which the behaviour could be returned to that in 8.4(2) and previous softwares.
So taking that into consideration I would be suprised that this kind of graphical change in the ASDM "Firewall" view wouldnt be noted in any documentation.
I would suggest waiting for either a reply directly from Cisco or opening a TAC case if you need a confirmation from Cisco directly.
- Jouni
04-22-2013 11:54 AM
Only thing I found related to the icmp and icmp6 was from the Bug Search Tool
Seems to be a enhancement request that was implemented

But again I cant tell from this information if it refers to this situation
This thing is listed on the 7.0(2) ASDM release notes
http://www.cisco.com/en/US/docs/security/asdm/7_0/release/notes/rn70.html#wp461760
- Jouni
04-22-2013 11:57 AM
Now that's a great find - searching the bug DB for a feature request didn't dawn on me. Nice one!
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide