Solved

How exactly do I disable ping on a Cisco 1841?

Posted on 2007-11-29
2
1,724 Views
Last Modified: 2013-11-29
I am a router newbie who has a Cisco 1841 providing a point-to-point T1 connection to my ISP.  The router in question is failing a security audit because it has ICMP allowed.  It looks to me like ICMP is being denied, but when I try to ping the router I get a response saying "Reply from x.x.x.x: TTL expired in transit."

The portion of my ACL that pertains to ICMP looks like this:

access-list 105 permit icmp any any packet-too-big
access-list 105 permit icmp any any source-quench
access-list 105 permit icmp any any time-exceeded
access-list 105 permit icmp any any echo-reply
access-list 105 deny   icmp any any

Does the 'permit icmp any any echo-reply' override the 'deny icmp any any'?  I haven't really delved into what the other icmp permits are doing, either.  

Thanks,
Scott
0
Comment
Question by:corptech
2 Comments
 
LVL 50

Accepted Solution

by:
Don Johnston earned 125 total points
ID: 20375611
Does the 'permit icmp any any echo-reply' override the 'deny icmp any any'?

No.

The TTL exceeded message is being allowed by the "permit icmp any any time-exceeded" line.

access-list 105 permit icmp any any packet-too-big
! allows the message that it's received a packet that it can't forward because it's too big
access-list 105 permit icmp any any source-quench
! allows the message that a host that the router can't keep up with the it's receiving
access-list 105 permit icmp any any time-exceeded
!see above
access-list 105 permit icmp any any echo-reply
! allows replies to pings
access-list 105 deny   icmp any any
! stops any icmp messages

Here a page that has details on ICMP messages.

http://www.softpanorama.org/Net/Internet_layer/icmp.shtml
0
 
LVL 2

Author Closing Comment

by:corptech
ID: 31411731
perfect donjohnston.  thanks a lot.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question