ASA/PIX Inbound ICMP through the PIX is denied by default;
outbound ICMP is permitted, but the incoming reply is denied by default.

Pings Outbound

Responses to outbound ICMP can be permitted with either a conduit statement or an
access-list statement, based on which you use on the PIX. Do not mix conduits and access lists.

This example shows how to permit responses to ICMP requests initiated by device 10.1.1.5 inside
(static to 192.168.1.5) from all devices outside:

static (inside,outside) 192.168.1.5 10.1.1.5 netmask 255.255.255.255 0 0

!— and either

conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 echo-reply
conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 source-quench
conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 unreachable
conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 time-exceeded

!— or

access-list 101 permit icmp any host 192.168.1.5 echo-reply
access-list 101 permit icmp any host 192.168.1.5 source-quench
access-list 101 permit icmp any host 192.168.1.5 unreachable
access-list 101 permit icmp any host 192.168.1.5 time-exceeded
access-group 101 in interface outside

Pings Inbound

Pings initiated from the outside, or another low security interface of the PIX,
are denied be default. The pings can be allowed by the use of static and
access lists or access lists alone.

In this example, one server on the inside of the PIX is made accessible to external pings.
A static translation is created between the inside address (10.1.1.5) and the outside address (192.168.1.5).

pix(config)#static (inside,outside) 192.168.1.5 10.1.1.5 netmask 255.255.255.255
pix(config)#access-list 101 permit icmp any host 192.168.1.5 echo
pix(config)#access-group 101 in interface outside

 

In this example, the PIX cannot send echo replies in response to echo requests:

icmp deny any echo outside

As with access lists, in the absence of permit statements, there is also an implicit deny of all other ICMP traffic.

This command permits pings from the network immediately outside the PIX:

icmp permit 192.168.1.0 255.255.255.0 echo outside

As with access lists, in the absence of permit statements, there is also an implicit deny of all other ICMP traffic.
!
!
To ping the pix inside ip address from the other side of the tunnel,
you will need to enable “management-access inside“.
!
As far as pinging from the pix, you would need to create an IPSEC SA that
contains the pix outside ip address since the source of the ICMP packet will
be the outside interface address.
eq :

ping 172.20.186.1 inside
ping 80.233.56.1 outside