07-05-2020 10:17 PM
Hi gentlemen,
I need configuration for these 2 scenarios ASA- Dynamic NAT & PAT. Can somebody provide me with links to these scenarios please.
P.S: I have another question about ASA: why ICMP & Traceroute commands are disabled for inspection by default.
Thanks in advance
Solved! Go to Solution.
07-05-2020 11:27 PM
Hi there,
the following document covers the scenarios you mention:
Regarding ICMP and traceroute, both use stateless packets, something that the ASA doesn't track by default. My guess as to why inspection is disabled by default instead of tracking the packets would be to prevent the firewall from overwhelmed by that packet type.
cheers,
Seb.
07-05-2020 11:27 PM
Hi there,
the following document covers the scenarios you mention:
Regarding ICMP and traceroute, both use stateless packets, something that the ASA doesn't track by default. My guess as to why inspection is disabled by default instead of tracking the packets would be to prevent the firewall from overwhelmed by that packet type.
cheers,
Seb.
07-07-2020 12:05 AM
Do u mean its because of security reason?
07-07-2020 12:45 AM
Yes, its not a good idea to make your security device susceptible to denial of service type attack.
07-07-2020 05:06 AM
07-07-2020 05:48 AM
The ASA does not support GETVPN. For multicast guides the ASA CLI configuration books are a good place to start:
07-13-2020 01:58 AM
07-13-2020 07:17 AM
Yes, it is a typo. The diagram and config describe the same process. The leading paragraph need the translated outside IP address swapped around.
cheers,
Seb.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide