Solved

Cisco FWSM Denying Outbound ICMP (type 3)

Posted on 2009-05-05
1
1,018 Views
Last Modified: 2012-05-06
I have a Cisco firewall that is logging the following SYSLOG (about 15 per second):

Denied ICMP type=3, from laddr 10.1.72.30 on interface Inside539 to 67.128.185.202: no matching session

The destination IP of 67.128.185.202 varies, but the source is always the same.  I have found that the customer has SolarWinds installed on this host.  Why would the firewall be blocking OUTBOUND packets when I have an outbound ACL (applied to Inside539 interface)?

access-list Inside539_access_in extended permit ip 10.1.72.0 255.255.255.0 any
0
Comment
Question by:Venyu
1 Comment
 
LVL 32

Accepted Solution

by:
harbor235 earned 500 total points
ID: 24314364


is someone scanning from inside your network outbound? Aah solarwinds, someone is scanning

ICMP type 3 is destination unreachable, do you have a default route outbound, can you route to 67.128.185.202 (try pinging from the same subnet) 15 per second is a pretty good rate.

The firewall will approximate icmp connections, if the icmp message does not have a nmatching component you can get this message, i am not sure how someone generates the type 3 unsolicitated unless they have a packet generator.

Coupls of things, sniff the traffic coming from the suspected port and see ehats coming in and going out

harbor235 ;}
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Questions on windows ports 13 75
routing between two sonicwall NSA 2600's connected via patch cable on x2 port 14 42
Watchguard XTM 2 70
Tagging ports on a managed switch 6 50
Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now