03-06-2014 02:57 PM - edited 03-11-2019 08:54 PM
I was testing to see if I was having asymmetric routing to an ASA inside interface from a router. The following does not work and
on the ASA I get error ASA-3-313001: Denied ICMP type=8, code=0 ....
R1#ping Protocol [ip]: Target IP address: x.x.x.x Repeat count [5]: 2 Datagram size [100]: Timeout in seconds [2]: Extended commands [n]: y Source address or interface: n.n.n.n Type of service [0]: Set DF bit in IP header? [no]: Validate reply data? [no]: Data pattern [0xABCD]: Loose, Strict, Record, Timestamp, Verbose[none]: RNumber of hops [ 9 ]: Loose, Strict, Record, Timestamp, Verbose[RV]: Sweep range of sizes [n]: Type escape sequence to abort. Sending 2, 100-byte ICMP Echos to x.x.x.x, timeout is 2 seconds: Packet sent with a source address of n.n.n.n Packet has IP options: Total option bytes= 39, padded length=40
Record route: <*> (0.0.0.0) (0.0.0.0) (0.0.0.0) (0.0.0.0) (0.0.0.0) (0.0.0.0) (0.0.0.0) (0.0.0.0) (0.0.0.0)
Request 0 timed outRequest 1 timed out
However this works fine when I do a simple source ping.
R1# ping x.x.x.x source n.n.n.n
Anyone have any idea what the ASA might be doing with the Record option?
03-06-2014 04:46 PM
We are missing info,
Where is the router located?
What NAT do u have in place?
Looking for some Networking Assistance?
Contact me directly at jcarvaja@laguiadelnetworking.com
I will fix your problem ASAP.
Cheers,
Julio Carvajal Segura
http://laguiadelnetworking.com
03-07-2014 05:29 AM
Sorry I forgot to say this is strictly from a router ( 5 hops away) on the inside going to the ASA inside interface.
03-07-2014 06:40 AM
I think I figured it out. Max hop count allow is 9 here which results in the request timed out for the return path.
The error on the ASA though is questionable. Either way it is not a concrete test because of the > 9 hops
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide