Solved

Enable icmp ping on ASA 5505 WAN interface

Posted on 2008-10-09
3
17,136 Views
Last Modified: 2014-08-14
Is it possible to enable ICMP ping on my WAN interface for my ASA 5505 as I want to do some diagnosis and performance analysis.

Many thanks.
0
Comment
Question by:AXISHK
3 Comments
 
LVL 4

Assisted Solution

by:TNL_Engr
TNL_Engr earned 100 total points
ID: 22679321
Yes.  If you are working from the ASDM GUI the setting is found under:

Configuration: Device Management: ICMP
Click Add, and select the outside Interface, permit 0.0.0.0 0.0.0.0

From the CLI, it looks like this:
icmp permit any Outside
0
 
LVL 12

Accepted Solution

by:
Pugglewuggle earned 400 total points
ID: 22682934
The thing is that by default, ASAs block all ICMP replies.
To allow this, you need to add this to your access-list:
access-list outside_access_in permit icmp any any echo-reply
access-group outside_access_in in interface outside

I never use the separate icmp permit command because it allows ALL ICMP messages to pass, which can be a potential security threat - not just the ping replies.
Cheers! Let me know if you have any questions
0
 

Expert Comment

by:jongrew
ID: 40260995
I have used the commands in the accepted solution but I still cannot ping the ASA from outside.  Does this command work in version 8.4(4)
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
Concerto provides fully managed cloud services and the expertise to provide an easy and reliable route to the cloud. Our best-in-class solutions help you address the toughest IT challenges, find new efficiencies and deliver the best application expe…

948 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now