cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
369
Views
0
Helpful
1
Replies

How to disable ICMP

shivaram840
Level 1
Level 1

Hi friends,

i am getting in logs , is this danger ? 

%ASA-6-302020: Built {in | out}bound ICMP connection for faddr {faddr 
| icmp_seq_num} [(idfw_user)] gaddr {gaddr | cmp_type} laddr laddr [(idfw_user)]

An ICMP session was established in the fast-path when stateful ICMP was enabled using the inspect icmp command.

please look the attached screenshot ?

Thanks,

Shiva

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

That's the normal syslog message one would expect when ICMP is allowed (via inspect action in the MPF) and syslog level 6 or higher is enabled.

We typically don't recommend level 6 syslog unless required for troubleshooting or auditing purposes. It will generate tens of thousands of messages per hour on any moderately loaded firewall and make identification of operational issues more difficult as it is that much harder to separate "signal" from "noise".