{"id":957,"date":"2010-10-30T13:38:18","date_gmt":"2010-10-30T13:38:18","guid":{"rendered":"http:\/\/wiki.freeiz.com\/?p=957"},"modified":"2016-08-09T12:04:52","modified_gmt":"2016-08-09T12:04:52","slug":"icmp-access-list-2","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2010\/10\/30\/icmp-access-list-2\/","title":{"rendered":"ICMP Access-List"},"content":{"rendered":"<p>ASA\/PIX Inbound ICMP through the PIX is denied by default;<br \/>\noutbound ICMP is permitted, but the incoming reply is denied by default.<\/p>\n<p><strong>Pings Outbound<\/strong><\/p>\n<p>Responses to outbound ICMP can be permitted with either a conduit statement or an<br \/>\naccess-list statement, based on which you use on the PIX. Do not mix conduits and access lists.<\/p>\n<p>This example shows how to permit responses to ICMP requests initiated by device 10.1.1.5 inside<br \/>\n(static to 192.168.1.5) from all devices outside:<\/p>\n<p><strong>static (inside,outside) 192.168.1.5 10.1.1.5 netmask 255.255.255.255 0 0<\/strong><\/p>\n<p>!&#8212; and either<\/p>\n<p><strong>conduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 echo-reply<br \/>\nconduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 source-quench<br \/>\nconduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 unreachable<br \/>\nconduit permit icmp 192.168.1.5 255.255.255.255 0.0.0.0 0.0.0.0 time-exceeded<\/strong><\/p>\n<p>!&#8212; or<\/p>\n<p><strong>access-list 101 permit icmp any host 192.168.1.5 echo-reply<br \/>\naccess-list 101 permit icmp any host 192.168.1.5 source-quench<br \/>\naccess-list 101 permit icmp any host 192.168.1.5 unreachable<br \/>\naccess-list 101 permit icmp any host 192.168.1.5 time-exceeded<br \/>\naccess-group 101 in interface outside<\/strong><\/p>\n<p><strong>Pings Inbound<\/strong><\/p>\n<p>Pings initiated from the outside, or another low security interface of the PIX,<br \/>\nare denied be default. The pings can be allowed by the use of static and<br \/>\naccess lists or access lists alone.<\/p>\n<p>In this example, one server on the inside of the PIX is made accessible to external pings.<br \/>\nA static translation is created between the inside address (10.1.1.5) and the outside address (192.168.1.5).<\/p>\n<p><strong>pix(config)#static (inside,outside) 192.168.1.5 10.1.1.5 netmask 255.255.255.255<br \/>\npix(config)#access-list 101 permit icmp any host 192.168.1.5 echo<br \/>\npix(config)#access-group 101 in interface outside<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p>In this example, the PIX cannot send echo replies in response to echo requests:<\/p>\n<blockquote>\n<pre><strong>icmp deny any echo outside<\/strong><\/pre>\n<\/blockquote>\n<p>As with access lists, in the absence of <strong>permit<\/strong> statements, there is also an implicit deny of all other ICMP traffic.<\/p>\n<p>This command permits pings from the network immediately outside the PIX:<\/p>\n<blockquote>\n<pre><strong>icmp permit 192.168.1.0 255.255.255.0 echo outside<\/strong><\/pre>\n<\/blockquote>\n<p>As with access lists, in the absence of <strong>permit<\/strong> statements, there is also an implicit deny of all other ICMP traffic.<br \/>\n!<br \/>\n!<br \/>\nTo ping the pix inside ip address from the other side of the tunnel,<br \/>\nyou will need to enable &#8220;<strong>management-access inside<\/strong>&#8220;.<br \/>\n!<br \/>\nAs far as pinging from the pix, you would need to create an IPSEC SA that<br \/>\ncontains the pix outside ip address since the source of the ICMP packet will<br \/>\nbe the outside interface address.<br \/>\neq :<\/p>\n<p>ping 172.20.186.1 inside<br \/>\nping 80.233.56.1 outside<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ASA\/PIX Inbound ICMP through the PIX is denied by default; outbound ICMP is permitted, but the incoming reply is denied by default. Pings Outbound Responses to outbound ICMP can be permitted with either a conduit statement or an access-list statement, based on which you use on the PIX. Do not mix conduits and access lists. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[344],"class_list":["post-957","post","type-post","status-publish","format-standard","hentry","category-cisco-routers","tag-icmp"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/957","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=957"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/957\/revisions"}],"predecessor-version":[{"id":4821,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/957\/revisions\/4821"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=957"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=957"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=957"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}