ASA/PIX Inbound ICMP through the PIX is denied by default;
outbound ICMP is permitted, but the incoming reply is denied by default.
Pings Outbound
Responses to outbound ICMP can be permitted with either a conduit statement or an
access-list statement, based on which you use on the PIX. Do not mix conduits and access lists.
This example shows how to permit responses to ICMP requests initiated by device 10.1.1.5 inside
(static to 192.168.1.5) from all devices outside:
static (inside,outside) 192.168.1.5 10.1.1.5 netmask 255.255.255.255 0 0
!— and either
conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 echo-reply
conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 source-quench
conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 unreachable
conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 time-exceeded
!— or
access-list 101 permit icmp any host 192.168.1.5 echo-reply
access-list 101 permit icmp any host 192.168.1.5 source-quench
access-list 101 permit icmp any host 192.168.1.5 unreachable
access-list 101 permit icmp any host 192.168.1.5 time-exceeded
access-group 101 in interface outside
Pings Inbound
Pings initiated from the outside, or another low security interface of the PIX,
are denied be default. The pings can be allowed by the use of static and
access lists or access lists alone.
In this example, one server on the inside of the PIX is made accessible to external pings.
A static translation is created between the inside address (10.1.1.5) and the outside address (192.168.1.5).
pix(config)#static (inside,outside) 192.168.1.5 10.1.1.5 netmask 255.255.255.255
pix(config)#access-list 101 permit icmp any host 192.168.1.5 echo
pix(config)#access-group 101 in interface outside
In this example, the PIX cannot send echo replies in response to echo requests:
icmp deny any echo outside
As with access lists, in the absence of permit statements, there is also an implicit deny of all other ICMP traffic.
This command permits pings from the network immediately outside the PIX:
icmp permit 192.168.1.0 255.255.255.0 echo outside
As with access lists, in the absence of permit statements, there is also an implicit deny of all other ICMP traffic.
!
!
To ping the pix inside ip address from the other side of the tunnel,
you will need to enable “management-access inside“.
!
As far as pinging from the pix, you would need to create an IPSEC SA that
contains the pix outside ip address since the source of the ICMP packet will
be the outside interface address.
eq :
ping 172.20.186.1 inside
ping 80.233.56.1 outside
Comments
(There are currently no comments for this post.)