01-19-2015 06:52 AM - edited 03-07-2019 10:17 PM
Hello,
Since the asr 1001 is facing the internet i would like to disable the ping for security purpose. I understand I can create a ACL to stop the ping packets from internet. Once concern is this might cause the capacity issue.
Is there any other ways to disable the ping on the asr1001?
Thanks
Ray
01-19-2015 07:03 AM
Hi,
Is should not cause capacity issue. You can create an access-list and apply it to the interface facing the internet and block ICMP. It should be in "in" direction and also make sure you have all your permit statements before you putting in the deny statements.
HTH
01-19-2015 07:19 AM
ok. If that is the case, I do not worry about it then.
Thanks to reply.
01-19-2015 09:51 PM
For Internet edge, the ASRs I have configured out there have had ZBFW to protect the SELF zone as well as some inside zones.
If you are in to security like me and run some vulnerability scans (Qualys) in my case the results came back completely clean.
If it is only pings you want to stop a simple ACL will do but normally one would think about protecting the router in other ways too.
e.g. CoPP, ZBFW
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide